Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfjc-xr6c-c6vw

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

EPSS

Процентиль: 21%
0.00283
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-601

Связанные уязвимости

nvd
8 дней назад

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

EPSS

Процентиль: 21%
0.00283
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-601