Описание
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.36.2 (исключая)
cpe:2.3:a:ibenic:simple_giveaways:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 94%
0.13939
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
EPSS
Процентиль: 94%
0.13939
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79