Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjf7-gjcp-9frw

Опубликовано: 30 нояб. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

EPSS

Процентиль: 29%
0.00107
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

EPSS

Процентиль: 29%
0.00107
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352
CWE-79