Lucene search

K
cvePatchstackCVE-2023-25031
HistoryApr 07, 2023 - 12:15 p.m.

CVE-2023-25031

2023-04-0712:15:07
CWE-79
Patchstack
web.nvd.nist.gov
28
cve
2023
25031
auth
admin+
stored
cross-site scripting
xss
kiboko labs
arigato autoresponder
newsletter plugin

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

17.5%

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <=Β 2.7.1 versions.

Affected configurations

Nvd
Vulners
Node
kibokolabsarigato_autoresponder_and_newsletterRange≀2.7.1wordpress
VendorProductVersionCPE
kibokolabsarigato_autoresponder_and_newsletter*cpe:2.3:a:kibokolabs:arigato_autoresponder_and_newsletter:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "bft-autoresponder",
    "product": "Arigato Autoresponder and Newsletter",
    "vendor": "Kiboko Labs",
    "versions": [
      {
        "changes": [
          {
            "at": "2.7.1.1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "2.7.1",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

17.5%

Related for CVE-2023-25031