Cross-site scripting (XSS) vulnerability in name.html in easyXDM before 2.4.19 allows remote attackers to inject arbitrary web script or HTML via the location.hash value.
- http://seclists.org/fulldisclosure/2014/Feb/5
No PoCs found on GitHub currently.