Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vf6-5443-jww8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

EPSS

Процентиль: 48%
0.00247
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

EPSS

Процентиль: 48%
0.00247
Низкий

Дефекты

CWE-79