Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73xq-fm46-h4hh

Опубликовано: 21 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

EPSS

Процентиль: 44%
0.00215
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

EPSS

Процентиль: 44%
0.00215
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79