Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24610

Опубликовано: 27 сент. 2021
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cozmoslabs:translatepress:*:*:*:*:*:wordpress:*:*
Версия до 2.0.9 (исключая)

EPSS

Процентиль: 81%
0.01572
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

EPSS

Процентиль: 81%
0.01572
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79