Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjcj-g2w6-gp9q

Опубликовано: 16 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

EPSS

Процентиль: 97%
0.41452
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

EPSS

Процентиль: 97%
0.41452
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79