4.3

CVE-2011-5082

s2Member® Framework (Membership, Member Level Roles, Access Capabilities, PayPal Members) < 111220 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
Mögliche Gegenmaßnahme
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions: Update to version 111220, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
Version [*, 111220)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
S2memberS2member Version <= 111216
   WordpressWordpress
S2memberS2member Version110604
   WordpressWordpress
S2memberS2member Version110605
   WordpressWordpress
S2memberS2member Version110606
   WordpressWordpress
S2memberS2member Version110617
   WordpressWordpress
S2memberS2member Version110620
   WordpressWordpress
S2memberS2member Version110708
   WordpressWordpress
S2memberS2member Version110709
   WordpressWordpress
S2memberS2member Version110710
   WordpressWordpress
S2memberS2member Version110731
   WordpressWordpress
S2memberS2member Version110812
   WordpressWordpress
S2memberS2member Version110815
   WordpressWordpress
S2memberS2member Version110912
   WordpressWordpress
S2memberS2member Version110913
   WordpressWordpress
S2memberS2member Version110915
   WordpressWordpress
S2memberS2member Version110926
   WordpressWordpress
S2memberS2member Version110927
   WordpressWordpress
S2memberS2member Version111002
   WordpressWordpress
S2memberS2member Version111003
   WordpressWordpress
S2memberS2member Version111011
   WordpressWordpress
S2memberS2member Version111017
   WordpressWordpress
S2memberS2member Version111029
   WordpressWordpress
S2memberS2member Version111105
   WordpressWordpress
S2memberS2member Version111206
   WordpressWordpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.486
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.