Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqq6-8mr8-33fw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)

The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)

EPSS

Процентиль: 81%
0.01484
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)

EPSS

Процентиль: 81%
0.01484
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352
CWE-79