Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vvr-3g53-9w72

Опубликовано: 26 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

EPSS

Процентиль: 38%
0.0017
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.5
nvd
почти 2 года назад

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

EPSS

Процентиль: 38%
0.0017
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-79