Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8m6-8wfx-7hpr

Опубликовано: 07 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks

The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79