Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v5c-v328-xq45

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

EPSS

Процентиль: 56%
0.00332
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 5 лет назад

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

EPSS

Процентиль: 56%
0.00332
Низкий

Дефекты

CWE-79