Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view