Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6v6-784c-hpw9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

EPSS

Процентиль: 57%
0.00348
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
больше 4 лет назад

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

EPSS

Процентиль: 57%
0.00348
Низкий

Дефекты

CWE-79