Quote Originally Posted by briansol View Post
over-paranoid IMO.

xss isn't going to get you hacked... only stupid users will fall for it and it won't effect your site, only their machine basically...
OR, they enter their login information in an xss iframe of some sort...
so, just tell your staff to be careful about how they log in and you have nothing to worry about IMO.

I won't b upgrading.
Thats what I thought, but on one of my sites where I am the only admin. My account got hacked by spider team yesterday. they were able to change the pass and email using this exploit. Now I don't click on any links nor enter my password in any pop up windows, so they were some how able to exploit this through a shell. I have since renewed my access and upgraded the site from 3.7.3 to 3.8 beta to test it out.

I would recommend upgrading or applying the patch.