Reported over three years ago and allegedly still not properly fixed, the vulnerability enables attacks to execute JavaScript ...