Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7g2w-7rc7-vmrj

Опубликовано: 06 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

EPSS

Процентиль: 34%
0.00138
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

EPSS

Процентиль: 34%
0.00138
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79