Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v9q-rjxq-3952

Опубликовано: 25 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
около 4 лет назад

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79