4.8

CVE-2019-16522

Exploit

EU Cookie Law <= 3.1.2 - Authenticated Stored Cross-Site Scripting

The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.
Mögliche Gegenmaßnahme
EU Cookie Law for GDPR/CCPA: Update to version 3.1.3, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt EU Cookie Law for GDPR/CCPA
Version [*, 3.1.3)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eu Cookie Law ProjectEu Cookie Law SwPlatformwordpress Version <= 3.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.572
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.