Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qfjr-7vg6-v99x

Опубликовано: 02 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

EPSS

Процентиль: 98%
0.47815
Средний

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
около 3 лет назад

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

EPSS

Процентиль: 98%
0.47815
Средний

4.7 Medium

CVSS3

Дефекты

CWE-79