Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23707

Опубликовано: 23 мар. 2023
Источник: nvd
CVSS3: 5.9
CVSS3: 5.4
EPSS Низкий

Описание

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin <= 2.7.1 versions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:awsm:embed_any_document:*:*:*:*:*:wordpress:*:*
Версия до 2.7.1 (включая)

EPSS

Процентиль: 21%
0.0007
Низкий

5.9 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin <= 2.7.1 versions.

EPSS

Процентиль: 21%
0.0007
Низкий

5.9 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79