Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmxp-xm59-3rjf

Опубликовано: 27 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets allows Stored XSS.This issue affects Volunteer Sign Up Sheets: from n/a before 5.5.5.

The patch is available exclusively on GitHub at https://github.com/dbarproductions/pta-volunteer-sign-up-sheets , as the vendor encounters difficulties using SVN to deploy to the WordPress.org repository.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets allows Stored XSS.This issue affects Volunteer Sign Up Sheets: from n/a before 5.5.5.

The patch is available exclusively on GitHub at https://github.com/dbarproductions/pta-volunteer-sign-up-sheets , as the vendor encounters difficulties using SVN to deploy to the WordPress.org repository.

EPSS

Процентиль: 8%
0.0003
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.9
nvd
9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets allows Stored XSS.This issue affects Volunteer Sign Up Sheets: from n/a before 5.5.5. The patch is available exclusively on GitHub at https://github.com/dbarproductions/pta-volunteer-sign-up-sheets , as the vendor encounters difficulties using SVN to deploy to the WordPress.org repository.

EPSS

Процентиль: 8%
0.0003
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-79