Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgw8-98j5-vg4c

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-79