Lucene search

K
wpvulndbWpvulndbWPVDB-ID:ECD9E89D-C82C-4492-9C1E-5299EAC99531
HistoryJun 20, 2023 - 12:00 a.m.

Mailtree Log Mail < 1.0.1 - Unauthenticated Stored Cross-Site Scripting

2023-06-2000:00:00
wpscan.com
10
mailtree; log mail; unauthenticated; stored cross-site scripting; input sanitization; arbitrary web scripts; compromised page; software

EPSS

0.001

Percentile

46.2%

The plugin does not properly sanitize and escape the input received through the email subject, leading to potential Stored Cross-Site Scripting (XSS). This can result in the execution of arbitrary web scripts whenever a user accesses a compromised page.

EPSS

0.001

Percentile

46.2%

Related for WPVDB-ID:ECD9E89D-C82C-4492-9C1E-5299EAC99531