Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3rv-7532-9gg6

Опубликовано: 16 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

EPSS

Процентиль: 85%
0.02517
Низкий

8.3 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.3
nvd
больше 1 года назад

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

EPSS

Процентиль: 85%
0.02517
Низкий

8.3 High

CVSS3

Дефекты

CWE-918