Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qj7-xwrg-68v3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.8). Stored XSS possible via unsanitized input fields of the plugin settings, some of the payloads could make the frontend and the backend inaccessible.

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.8). Stored XSS possible via unsanitized input fields of the plugin settings, some of the payloads could make the frontend and the backend inaccessible.

EPSS

Процентиль: 43%
0.00208
Низкий

8.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.6
nvd
больше 4 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.

EPSS

Процентиль: 43%
0.00208
Низкий

8.2 High

CVSS3

Дефекты

CWE-79