Логотип exploitDog
bind:CVE-2022-1617
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1617

Количество 2

Количество 2

nvd логотип

CVE-2022-1617

около 2 лет назад

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qp39-g94h-cxxf

около 2 лет назад

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-1617

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-qp39-g94h-cxxf

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

CVSS3: 6.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу