Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rg7-7m6h-7jqr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.

EPSS

Процентиль: 47%
0.00244
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.

CVSS3: 5.4
fstec
больше 4 лет назад

Уязвимость модуля «Create poll» («Создать опрос») плагина YOP Poll системы управления содержимым сайта WordPress, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

EPSS

Процентиль: 47%
0.00244
Низкий

Дефекты

CWE-79