Microweber prior to 1.2.12 contains a stored cross-site scripting vulnerability via the Type parameter in the body of POST request, which is triggered by Add/Edit Tax.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view