Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| W-agora | W-agora | 4.1.5 (including) | 4.1.5 (including) |