Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-1494

Опубликовано: 17 фев. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:colorlib:fancybox:*:*:*:*:*:wordpress:*:*
Версия до 3.0.2 (включая)

EPSS

Процентиль: 89%
0.04563
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

EPSS

Процентиль: 89%
0.04563
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79