Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6243

Опубликовано: 22 июл. 2024
Источник: nvd
CVSS3: 4.8
CVSS3: 5.9
EPSS Низкий

Описание

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linksoftwarellc:html_forms:*:*:*:*:*:wordpress:*:*
Версия до 1.3.33 (исключая)

EPSS

Процентиль: 37%
0.00161
Низкий

4.8 Medium

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 1 года назад

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

EPSS

Процентиль: 37%
0.00161
Низкий

4.8 Medium

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-79