Lucene search

K
cvePatchstackCVE-2023-28499
HistoryNov 07, 2023 - 6:15 p.m.

CVE-2023-28499

2023-11-0718:15:08
CWE-79
Patchstack
web.nvd.nist.gov
26
cve-2023-28499
author+
stored xss
simonpedge
slide anything
responsive content
html slider
carousel
vulnerability

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

14.0%

Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.

Affected configurations

Nvd
Vulners
Node
simonpedgeslide_anything-responsive_content\/html_slider_and_carouselRange2.4.9
VendorProductVersionCPE
simonpedgeslide_anything-responsive_content\/html_slider_and_carousel*cpe:2.3:a:simonpedge:slide_anything-responsive_content\/html_slider_and_carousel:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "slide-anything",
    "product": "Slide Anything – Responsive Content / HTML Slider and Carousel",
    "vendor": "simonpedge",
    "versions": [
      {
        "lessThanOrEqual": "2.4.9",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

14.0%

Related for CVE-2023-28499