Lucene search

K
cvePatchstackCVE-2024-22153
HistoryJan 31, 2024 - 7:15 p.m.

CVE-2024-22153

2024-01-3119:15:09
CWE-79
Patchstack
web.nvd.nist.gov
18
cve-2024-22153
vulnerability
xss
web security
woocommerce
nvd

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

5.4

Confidence

High

EPSS

0

Percentile

14.0%

Improper Neutralization of Input During Web Page Generation (β€˜Cross-site Scripting’) vulnerability in Fahad Mahmood & Alexandre Faustino Stock Locations for WooCommerce allows Stored XSS.This issue affects Stock Locations for WooCommerce: from n/a through 2.5.9.

Affected configurations

Nvd
Vulners
Node
fahadmahmood8stock_locations_for_woocommerceRange<2.6.0wordpress
VendorProductVersionCPE
fahadmahmood8stock_locations_for_woocommerce*cpe:2.3:a:fahadmahmood8:stock_locations_for_woocommerce:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "stock-locations-for-woocommerce",
    "product": "Stock Locations for WooCommerce",
    "vendor": "Fahad Mahmood & Alexandre Faustino",
    "versions": [
      {
        "changes": [
          {
            "at": "2.6.0",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "2.5.9",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

5.4

Confidence

High

EPSS

0

Percentile

14.0%