Логотип exploitDog
bind:CVE-2023-4294
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4294

Количество 2

Количество 2

nvd логотип

CVE-2023-4294

больше 2 лет назад

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-57cx-38gf-xwrm

больше 2 лет назад

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4294

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVSS3: 6.1
32%
Средний
больше 2 лет назад
github логотип
GHSA-57cx-38gf-xwrm

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVSS3: 6.1
32%
Средний
больше 2 лет назад

Уязвимостей на страницу