Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gp2-g559-39jj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

EPSS

Процентиль: 88%
0.04044
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 5 лет назад

The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

EPSS

Процентиль: 88%
0.04044
Низкий

Дефекты

CWE-79