For every bounty won throughout May 2021, huntr will donate half towards Indian COVID relief.
forkcms is vulnerable to
XSS through adding new media.
<img src onerror=alert()>.
With an authenticated user, access:
Select the option
Online movies (Youtube, Vimeo, ...) and click on
source and put the payload into
Movie id or