Логотип exploitDog
bind:CVE-2024-3368
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-3368

Количество 2

Количество 2

nvd логотип

CVE-2024-3368

больше 1 года назад

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-f2gx-4fp8-9978

больше 1 года назад

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-3368

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-f2gx-4fp8-9978

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 6.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу