Lucene search

K
cveMitreCVE-2014-7182
HistoryOct 22, 2014 - 2:55 p.m.

CVE-2014-7182

2014-10-2214:55:06
CWE-79
mitre
web.nvd.nist.gov
28
cve
2014
7182
wp google maps
xss
vulnerabilities
wordpress
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.003

Percentile

71.0%

Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.

Affected configurations

Nvd
Node
codecabinwp_go_mapsRange6.0.26wordpress
VendorProductVersionCPE
codecabinwp_go_maps*cpe:2.3:a:codecabin:wp_go_maps:*:*:*:*:*:wordpress:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.003

Percentile

71.0%