Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r4w-wwx4-2399

Опубликовано: 19 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well

EPSS

Процентиль: 43%
0.00206
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well

EPSS

Процентиль: 43%
0.00206
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352