Lucene search

K
cve[email protected]CVE-2023-27443
HistoryJun 21, 2023 - 1:15 p.m.

CVE-2023-27443

2023-06-2113:15:09
CWE-79
web.nvd.nist.gov
19
cve-2023-27443
auth
contributor
stored cross-site scripting
xss
vulnerability
grant kimball
simple vimeo shortcode
plugin

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

0.0005 Low

EPSS

Percentile

17.7%

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2.9.1 versions.

Affected configurations

Vulners
NVD
Node
grant_kimballsimple_vimeo_shortcodeRange2.9.1

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "the-very-simple-vimeo-shortcode",
    "product": "Simple Vimeo Shortcode",
    "vendor": "Grant Kimball",
    "versions": [
      {
        "lessThanOrEqual": "2.9.1",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

0.0005 Low

EPSS

Percentile

17.7%

Related for CVE-2023-27443