Technology ❯ Software Development ❯ Web Development ❯ JavaScript
The August 6 security release fixes a high‑severity pre‑auth login XSS that can be escalated to server‑side PHP execution if an administrator is tricked into interacting with attacker content.