Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcvg-gpgp-f6cf

Опубликовано: 30 нояб. 2021
Источник: github
Github: Не прошло ревью

Описание

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-79