Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmj4-hxrq-f9wh

Опубликовано: 04 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

EPSS

Процентиль: 87%
0.03364
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
около 4 лет назад

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

EPSS

Процентиль: 87%
0.03364
Низкий

Дефекты

CWE-79