Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.
- http://securityreason.com/securityalert/3427
No PoCs found on GitHub currently.