Описание
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | not-affected  | 2.0.2-2 | 
| devel | not-affected  | 2.3.3-1ubuntu1 | 
| edgy | not-affected  | 2.0.4-2 | 
| feisty | not-affected  | 2.1.3-1ubuntu1.1 | 
| gutsy | not-affected  | 2.2.2-1ubuntu1.3 | 
| upstream | needs-triage  | 
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 ...
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
EPSS
4.3 Medium
CVSS2