Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g4w-5pr9-j65h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 5 лет назад

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-79