Cross-site scripting (XSS) vulnerability in fm.php in ONEdotOH Simple File Manager (SFM) 0.24a and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simple_file_manager | Onedotoh | * | 0.24a (including) |