Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3hv-p839-hwv6

Опубликовано: 25 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

EPSS

Процентиль: 80%
0.01396
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

EPSS

Процентиль: 80%
0.01396
Низкий

Дефекты

CWE-79