Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3w7-w9rh-w829

Опубликовано: 16 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-74