Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wxv-m6v8-9vx3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

EPSS

Процентиль: 84%
0.02314
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

EPSS

Процентиль: 84%
0.02314
Низкий

Дефекты

CWE-79