Описание
The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/admin.php file which allows unauthenticated attackers to inject arbitrary web scripts in versions up to, and including, 1.7.21.
Ссылки
- Patch
- Product
- Third Party Advisory
- Patch
- Product
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.22 (исключая)
cpe:2.3:a:andrewrminion:wp_youtube_live:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 87%
0.03226
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
почти 4 года назад
The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/admin.php file which allows unauthenticated attackers to inject arbitrary web scripts in versions up to, and including, 1.7.21.
EPSS
Процентиль: 87%
0.03226
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79