Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j4m-f87g-5r9r

Опубликовано: 27 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Complianz WordPress plugin vulnerable to cross-site scripting

The Complianz Premium WordPress plugin before 6.4.2 did not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Пакеты

Наименование

really-simple-plugins/complianz-gdpr

composer
Затронутые версииВерсия исправления

< 6.4.2

6.4.2

EPSS

Процентиль: 41%
0.00192
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

EPSS

Процентиль: 41%
0.00192
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79