Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hqq-j7p9-x52j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

EPSS

Процентиль: 97%
0.42184
Средний

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

EPSS

Процентиль: 97%
0.42184
Средний

Дефекты

CWE-79