Описание
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, executing code in the context of WordPress users viewing comments.
Ссылки
- Product
- ProductRelease Notes
- Third Party Advisory
Уязвимые конфигурации
EPSS
4.4 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, executing code in the context of WordPress users viewing comments.
EPSS
4.4 Medium
CVSS3
6.1 Medium
CVSS3