6.1

CVE-2012-10013

Kau-Boy Backend Localization Plugin backend_localization.php cross site scripting

Backend Localization <= 1.9 - Reflected Cross-Site Scripting

A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the file backend_localization.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is named 43dc96defd7944da12ff116476a6890acd7dd24b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227231.
Mögliche Gegenmaßnahme
Backend Localization: Update to version 2.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kau-boysBackend Localization SwPlatformwordpress Version < 2.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Backend Localization
Version 1.6.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.42
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
cna@vuldb.com 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/wp-plugins/kau-boys-backend-localization/commit/43dc96defd7944da12ff116476a6890acd7dd24b
Patch
https://github.com/wp-plugins/kau-boys-backend-localization/releases/tag/2.0
Release Notes
https://vuldb.com/?ctiid.227231
Third Party Advisory
https://vuldb.com/?id.227231
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/80fb6ac9-29af-4a11-ad2f-52cc1bfda6b3
Third Party Advisory