Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mp46-7x6q-f28m

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Woocommerce Cross-site Scripting via Additional tax classes field when taxes are enabled

When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

Пакеты

Наименование

woocommerce/woocommerce

composer
Затронутые версииВерсия исправления

< 5.2.0

5.2.0

EPSS

Процентиль: 59%
0.00377
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 4 лет назад

When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

EPSS

Процентиль: 59%
0.00377
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79