Описание
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
Ссылки
- https://github.com/duchenerc/artificial-intelligence/commit/c70631b1f80518411df2f88476041351110c6eacPatchThird Party Advisory
- Third Party Advisory
- https://github.com/duchenerc/artificial-intelligence/commit/c70631b1f80518411df2f88476041351110c6eacPatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.4 (исключая)
cpe:2.3:a:artificial_intelligence_project:artificial_intelligence:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 51%
0.00284
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
EPSS
Процентиль: 51%
0.00284
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79