Логотип exploitDog
bind:CVE-2021-24685
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24685

Количество 2

Количество 2

nvd логотип

CVE-2021-24685

больше 4 лет назад

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mcq-mff7-29h7

больше 3 лет назад

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24685

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mcq-mff7-29h7

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу