Описание
The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.6 (включая)
cpe:2.3:a:svgator:svgator:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 44%
0.00219
Низкий
4.6 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.6
github
больше 1 года назад
The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
EPSS
Процентиль: 44%
0.00219
Низкий
4.6 Medium
CVSS3
Дефекты
CWE-79