Quote:
Originally Posted by CAG CheechDogg
I know about XSS Vulnerabilities but how high risk is this if we don't add that fix of yours
|
Well, it's non-persistent, so it's not 100% harmful, but if somebody were to construct a URL, and get a mod, or an admin to click on it, they could steal your cookies, use it as there own, and they would be logged in as a mod / admin.
There are also more things they could do, exploit 0days in the browser etc.
I would recommend you apply my fix