Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmmh-2222-6j4v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue

The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79