Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44hj-f3hx-wwjr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.

Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.

EPSS

Процентиль: 39%
0.00178
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.

EPSS

Процентиль: 39%
0.00178
Низкий

Дефекты

CWE-79