Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx9f-2mhx-34vx

Опубликовано: 16 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

EPSS

Процентиль: 96%
0.22608
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

CVSS3: 6.1
fstec
почти 3 года назад

Уязвимость плагина Image Optimizer by 10web системы управления содержимым сайта WordPress, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 96%
0.22608
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79