Описание
Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
Уязвимые конфигурации
Конфигурация 1Версия до 1.15.3 (исключая)
cpe:2.3:a:wpcloudplugins:lets-box:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 73%
0.00782
Низкий
4.7 Medium
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79
Связанные уязвимости
github
около 4 лет назад
Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
EPSS
Процентиль: 73%
0.00782
Низкий
4.7 Medium
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79