Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D3C06E32-18E0-4CC2-A9BE-ABE4A2B54AA5
HistoryApr 04, 2024 - 12:00 a.m.

Yoo Slider < 2.2.0 - Reflected Cross-Site Scripting

2024-04-0400:00:00
wpscan.com
6
yoo slider
cross-site scripting
reflected
parameter
output
page
privilege
admin
plugin

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CPENameOperatorVersion
eq2.2.0

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:D3C06E32-18E0-4CC2-A9BE-ABE4A2B54AA5