Логотип exploitDog
bind:CVE-2022-2072
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-2072

Количество 2

Количество 2

nvd логотип

CVE-2022-2072

больше 3 лет назад

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mg3f-7p64-q5jf

больше 3 лет назад

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-2072

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mg3f-7p64-q5jf

The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу