Lucene search

K
cve[email protected]CVE-2023-1282
HistoryApr 17, 2023 - 1:15 p.m.

CVE-2023-1282

2023-04-1713:15:38
web.nvd.nist.gov
32
cve-2023-1282
drag and drop multiple file upload pro
contact form 7
wordpress plugin
remote storage integrations
cross-site scripting
security vulnerability

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

42.3%

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

Affected configurations

Vulners
NVD
Node
codedropzdrag_and_drop_multiple_file_upload_-_contact_form_7Range2.0.02.11.1
OR
codedropzdrag_and_drop_multiple_file_upload_-_contact_form_7Range5.0.0.05.0.6.4
VendorProductVersionCPE
codedropzdrag_and_drop_multiple_file_upload_\-_contact_form_7*cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_\-_contact_form_7:*:*:*:*:*:*:*:*
codedropzdrag_and_drop_multiple_file_upload_\-_contact_form_7*cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_\-_contact_form_7:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "2.0.0",
        "lessThan": "2.11.1"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "Unknown",
    "product": "Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "5.0.0.0",
        "lessThan": "5.0.6.4"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

42.3%

Related for CVE-2023-1282