Логотип exploitDog
bind:CVE-2023-4757
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4757

Количество 2

Количество 2

nvd логотип

CVE-2023-4757

около 2 лет назад

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-cj4r-mxq9-xgx5

около 2 лет назад

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4757

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-cj4r-mxq9-xgx5

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу