Lucene search

K
nvd[email protected]NVD:CVE-2023-33311
HistoryMay 28, 2023 - 7:15 p.m.

CVE-2023-33311

2023-05-2819:15:09
CWE-79
web.nvd.nist.gov
4
cve-2023-33311
authentication bypass
stored cross-site scripting
crm perks contact form entries
version 1.3.0

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.5%

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.

Affected configurations

Nvd
Node
crmperkscontact_form_entries_-_contact_form_7_wpforms_and_moreRange1.3.0wordpress
VendorProductVersionCPE
crmperkscontact_form_entries_-_contact_form_7_wpforms_and_more*cpe:2.3:a:crmperks:contact_form_entries_-_contact_form_7_wpforms_and_more:*:*:*:*:*:wordpress:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.5%

Related for NVD:CVE-2023-33311