Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26rv-cxmp-hwgh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

EPSS

Процентиль: 50%
0.00264
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

EPSS

Процентиль: 50%
0.00264
Низкий