Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qx8-7fxh-rjvj

Опубликовано: 09 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.

The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.

EPSS

Процентиль: 41%
0.00191
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.

EPSS

Процентиль: 41%
0.00191
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79