Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vv4w-4mwj-jh73

Опубликовано: 20 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

EPSS

Процентиль: 47%
0.00242
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

EPSS

Процентиль: 47%
0.00242
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79