Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26rv-cxmp-hwgh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

EPSS

Процентиль: 64%
0.01151
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

EPSS

Процентиль: 64%
0.01151
Низкий