4.3
CVE-2013-5711
- EPSS 1.64%
- Veröffentlicht 17.09.2013 12:04:16
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Design Approval System <= 3.6 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin before 3.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
Mögliche Gegenmaßnahme
Design Approval System: Update to version 3.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Slickremix ≫ Design Approval System Plugin Version <= 3.6
Slickremix ≫ Design Approval System Plugin Version1.0
Slickremix ≫ Design Approval System Plugin Version1.1
Slickremix ≫ Design Approval System Plugin Version1.2
Slickremix ≫ Design Approval System Plugin Version1.3
Slickremix ≫ Design Approval System Plugin Version1.4
Slickremix ≫ Design Approval System Plugin Version1.5
Slickremix ≫ Design Approval System Plugin Version1.6
Slickremix ≫ Design Approval System Plugin Version1.7
Slickremix ≫ Design Approval System Plugin Version1.8
Slickremix ≫ Design Approval System Plugin Version1.9
Slickremix ≫ Design Approval System Plugin Version2.0
Slickremix ≫ Design Approval System Plugin Version2.1
Slickremix ≫ Design Approval System Plugin Version2.2
Slickremix ≫ Design Approval System Plugin Version2.3
Slickremix ≫ Design Approval System Plugin Version2.4
Slickremix ≫ Design Approval System Plugin Version2.5
Slickremix ≫ Design Approval System Plugin Version2.6
Slickremix ≫ Design Approval System Plugin Version2.7
Slickremix ≫ Design Approval System Plugin Version2.8
Slickremix ≫ Design Approval System Plugin Version2.9
Slickremix ≫ Design Approval System Plugin Version3.0
Slickremix ≫ Design Approval System Plugin Version3.1
Slickremix ≫ Design Approval System Plugin Version3.2
Slickremix ≫ Design Approval System Plugin Version3.3
Slickremix ≫ Design Approval System Plugin Version3.4
Slickremix ≫ Design Approval System Plugin Version3.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Design Approval System
Version
*-3.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.64% | 0.732 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://archives.neohapsis.com/archives/bugtraq/2013-09/0055.html
http://wordpress.org/plugins/design-approval-system/other_notes/
https://www.wordfence.com/threat-intel/vulnerabilities/id/a52dc13f-50b3-4aa3-9924-beb75351673e