Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hhv-jmm7-4v3q

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Advanced Page Visit Counter WordPress plugin through 5.0.8 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

The Advanced Page Visit Counter WordPress plugin through 5.0.8 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

EPSS

Процентиль: 95%
0.16891
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

EPSS

Процентиль: 95%
0.16891
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79