Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmpw-3qc7-gg2j

Опубликовано: 28 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

EPSS

Процентиль: 94%
0.12126
Средний

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

EPSS

Процентиль: 94%
0.12126
Средний

Дефекты

CWE-79