Explore CMS v1.1 Reflected XSS: How a Community CMS's UserID Field Became the Attack Entry Point
The user/login.php and admin/login.php endpoints in Explore CMS v1.1 perform zero sanitization or validation on the UserID field. An attacker can trigger reflected XSS with a simple