Логотип exploitDog
bind:CVE-2023-4820
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4820

Количество 2

Количество 2

nvd логотип

CVE-2023-4820

больше 2 лет назад

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hfr4-7364-jv2q

больше 2 лет назад

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4820

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hfr4-7364-jv2q

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу