Логотип exploitDog
bind:CVE-2022-2171
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-2171

Количество 2

Количество 2

nvd логотип

CVE-2022-2171

больше 3 лет назад

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j2wv-pvcq-h7hf

больше 3 лет назад

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-2171

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-j2wv-pvcq-h7hf

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу