The plugin does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.
Put the following payload in the "php_id" field in the plugin's settings (/wp-admin/options-general.php?page=phtmanager): "><script>alert(/XSS/)</script>
ABISHEIK M
ABISHEIK M
Yes
2021-07-19 (about 1 years ago)
2021-07-19 (about 1 years ago)
2023-01-23 (about 4 months ago)