Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-2472
HistoryJun 05, 2023 - 2:15 p.m.

Cross site scripting

2023-06-0514:15:00
PRIOn knowledge base
www.prio-n.com
2
sendinblue
wordpress plugin
cross-site scripting
admin dashboard
wpml plugin

0.001 Low

EPSS

Percentile

24.8%

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

0.001 Low

EPSS

Percentile

24.8%

Related for PRION:CVE-2023-2472