A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.Referenceshttps://github.com/Indexhibit/indexhibit/issues/20