Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m86p-9hj8-wr2g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

EPSS

Процентиль: 58%
0.00363
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 5 лет назад

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

EPSS

Процентиль: 58%
0.00363
Низкий

Дефекты

CWE-79