Логотип exploitDog
bind:CVE-2022-0642
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-0642

Количество 2

Количество 2

nvd логотип

CVE-2022-0642

больше 3 лет назад

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-v6jq-x92p-hqjx

больше 3 лет назад

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0642

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-v6jq-x92p-hqjx

The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу