Логотип exploitDog
bind:CVE-2020-27851
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-27851

Количество 2

Количество 2

nvd логотип

CVE-2020-27851

около 5 лет назад

Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fcj2-rxqc-294c

больше 3 лет назад

Gravity Forms stored HTML injection vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-27851

Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).

CVSS3: 5.4
0%
Низкий
около 5 лет назад
github логотип
GHSA-fcj2-rxqc-294c

Gravity Forms stored HTML injection vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу