Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmrq-4p99-j6hr

Опубликовано: 29 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

EPSS

Процентиль: 78%
0.01135
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

EPSS

Процентиль: 78%
0.01135
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79