Описание
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-6465
- https://packetstormsecurity.com/files/146174/WordPress-Propertyhive-1.4.14-Cross-Site-Scripting.html
- https://wordpress.org/plugins/propertyhive/#developers
- https://wordpress.org/support/topic/wordpress-propertyhive-1-4-14-cross-site-scripting
- https://wpvulndb.com/vulnerabilities/9020
Связанные уязвимости
CVSS3: 6.1
nvd
около 8 лет назад
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.