Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8622

Опубликовано: 12 сент. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce validation on the preview functionality. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:amcharts:amcharts\:_charts_and_maps:*:*:*:*:*:wordpress:*:*
Версия до 1.4.5 (исключая)

EPSS

Процентиль: 73%
0.00742
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 1 года назад

The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce validation on the preview functionality. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

EPSS

Процентиль: 73%
0.00742
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79