Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8pvr-vj93-gj3v

Опубликовано: 15 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

EPSS

Процентиль: 48%
0.00253
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 2 лет назад

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
nvd
больше 2 лет назад

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

EPSS

Процентиль: 48%
0.00253
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79