Описание
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
Ссылки
- Third Party AdvisoryVDB Entry
- Product
- ExploitThird Party Advisory
- Third Party AdvisoryVDB Entry
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.6.2 (включая)
cpe:2.3:a:wp-code-highlightjs_project:wp-code-highlightjs:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 72%
0.00735
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
EPSS
Процентиль: 72%
0.00735
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-79