Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8pm-86rm-q74w

Опубликовано: 22 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

EPSS

Процентиль: 87%
0.03161
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting

EPSS

Процентиль: 87%
0.03161
Низкий

Дефекты

CWE-79