XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.Referenceshttps://www.interchangecommerce.orghttps://www.interchangecommerce.org/i/dev/news?mv_arg=00064