Lucene search

K
nvd[email protected]NVD:CVE-2023-28792
HistoryApr 07, 2023 - 3:15 p.m.

CVE-2023-28792

2023-04-0715:15:08
CWE-79
web.nvd.nist.gov
4
cve-2023-28792
unauthenticated
cross-site scripting
i thirteen web solution
continuous image carousel
lightbox plugin

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.6%

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin <= 1.0.15 versions.

Affected configurations

Nvd
Node
i13websolutioncontinuous_image_carosel_with_lightboxRange<1.0.16wordpress
VendorProductVersionCPE
i13websolutioncontinuous_image_carosel_with_lightbox*cpe:2.3:a:i13websolution:continuous_image_carosel_with_lightbox:*:*:*:*:*:wordpress:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.6%

Related for NVD:CVE-2023-28792