Логотип exploitDog
bind:CVE-2022-3904
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3904

Количество 2

Количество 2

nvd логотип

CVE-2022-3904

около 3 лет назад

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-cjcj-g2w6-gp9q

около 3 лет назад

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3904

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVSS3: 6.1
41%
Средний
около 3 лет назад
github логотип
GHSA-cjcj-g2w6-gp9q

The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

CVSS3: 6.1
41%
Средний
около 3 лет назад

Уязвимостей на страницу