This issue affects an unknown functionality of the file suggest-listing.php. The manipulation of the argument title with an unknown input leads to a cross site scripting vulnerability.
Multiple cross-site scripting (XSS) vulnerabilities in eSyndiCat Directory 2.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter to (1) suggest-category.php and (2) suggest-listing.php.
Horology - The Index enthusiastically encourages visitors to suggestlistings for these pages. The suggested link may be a website that you maintain or it may be any website that you believe would be interesting to others.