
Proof-of-concept for CVE-2021-38603: stored cross-site scripting (XSS) vulnerability in PluXML's profile edit page. Demonstrates injection via the Information field, triggered on user-created pages.
A stored cross site scripting vulnerability is present on the Profile edit page in the Information: field for each user.

Once inserted, XSS can be triggered by visiting any page/article created by that particular user.
