Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mxq8-qjm4-g6gq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue

EPSS

Процентиль: 56%
0.00332
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 5 лет назад

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue

EPSS

Процентиль: 56%
0.00332
Низкий

Дефекты

CWE-79