The fact
An attacker can exploit a Cross-Site Scripting vulnerability through the Held Messages pop-up.
This allows the execution of JavaScript code on the affected site.
Click the link to read an article on the topic:
An attacker can exploit a Cross-Site Scripting vulnerability through the Held Messages pop-up.
This allows the execution of JavaScript code on the affected site.