Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-45625

Опубликовано: 09 сент. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:incsub:forminator:*:*:*:*:*:wordpress:*:*
Версия до 1.34.1 (исключая)

EPSS

Процентиль: 48%
0.00251
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 1 года назад

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.

EPSS

Процентиль: 48%
0.00251
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79