Логотип exploitDog
bind:CVE-2023-6485
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6485

Количество 2

Количество 2

nvd логотип

CVE-2023-6485

около 2 лет назад

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-p5mw-mg37-2vrh

около 2 лет назад

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6485

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVSS3: 5.4
2%
Низкий
около 2 лет назад
github логотип
GHSA-p5mw-mg37-2vrh

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVSS3: 5.4
2%
Низкий
около 2 лет назад

Уязвимостей на страницу