Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghrx-3g4w-h4hh

Опубликовано: 26 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

EPSS

Процентиль: 52%
0.00288
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

EPSS

Процентиль: 52%
0.00288
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79