Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38344

Опубликовано: 14 окт. 2021
Источник: nvd
CVSS3: 6.4
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:brizy:brizy-page_builder:*:*:*:*:*:*:*:*
Версия до 2.3.11 (включая)

EPSS

Процентиль: 38%
0.00171
Низкий

6.4 Medium

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.

EPSS

Процентиль: 38%
0.00171
Низкий

6.4 Medium

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79