4.3

CVE-2014-7182

Exploit

WP Google Maps <= 6.0.26 - Reflected Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
Mögliche Gegenmaßnahme
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map: Update to version 6.0.27, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CodecabinWp Go Maps SwPlatformwordpress Version <= 6.0.26
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
Version [*, 6.0.27)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.46% 0.823
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://packetstormsecurity.com/files/128694/WordPress-WP-Google-Maps-6.0.26-Cross-Site-Scripting.html
Third Party Advisory
Exploit
VDB Entry
http://www.securityfocus.com/archive/1/533699/100/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/70597
Third Party Advisory
VDB Entry
https://wordpress.org/plugins/wp-google-maps/changelog
Product
Release Notes
https://www.htbridge.com/advisory/HTB23236
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/17d3a2e4-d6f3-4302-91b0-2408ccd8958a
Third Party Advisory