Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q47-vc82-p724

Опубликовано: 27 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

EPSS

Процентиль: 68%
0.00576
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

EPSS

Процентиль: 68%
0.00576
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79