Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g623-mj4w-fprv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

EPSS

Процентиль: 88%
0.04148
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

EPSS

Процентиль: 88%
0.04148
Низкий

Дефекты

CWE-79