Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3x5m-695g-v76h

Опубликовано: 14 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message

The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message

EPSS

Процентиль: 78%
0.01134
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message

EPSS

Процентиль: 78%
0.01134
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79