4.3

CVE-2014-6243

Exploit

EWWW Image Optimizer <= 2.0.1 - Reflected Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message.
Mögliche Gegenmaßnahme
EWWW Image Optimizer: Update to version 2.0.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt EWWW Image Optimizer
Version *-2.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.06% 0.789
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://packetstormsecurity.com/files/128621/WordPress-EWWW-Image-Optimizer-2.0.1-Cross-Site-Scripting.html
Exploit
http://www.securityfocus.com/archive/1/533641/100/0/threaded
http://www.securityfocus.com/bid/70190
https://wordpress.org/plugins/ewww-image-optimizer/changelog
Patch
https://www.htbridge.com/advisory/HTB23234
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/b5b24f80-d3a4-452b-bc83-3576bdc62829
Third Party Advisory