Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g78w-xr4j-vmwx

Опубликовано: 02 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Contact Form 7 Skins WordPress plugin through 2.5.0 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

The Contact Form 7 Skins WordPress plugin through 2.5.0 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

EPSS

Процентиль: 78%
0.01155
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

EPSS

Процентиль: 78%
0.01155
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79