Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv7x-h3w5-m6h9

Опубликовано: 18 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79