Логотип exploitDog
bind:CVE-2022-1938
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1938

Количество 2

Количество 2

nvd логотип

CVE-2022-1938

больше 3 лет назад

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9xww-pc5r-jrpc

больше 3 лет назад

The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-1938

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-9xww-pc5r-jrpc

The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу