A Letters to Editor section in a publication was found to be vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient input validation. This allowed attackers to inject malicious scripts into published letters, potentially compromising readers' browsers and stealing sensitive data. The vulnerability affected the publication's website and its readers globally.