6.1

CVE-2021-25107

Exploit

Form Store to DB < 1.1.1 - Unauthenticated Stored Cross-Site Scripting

Form Store to DB <= 1.1.0 - Stored Cross-Site Scripting

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin
Mögliche Gegenmaßnahme
Form Store to DB: Update to version 1.1.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AccesspressthemesForm Store To Db SwPlatformwordpress Version < 1.1.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Form Store to DB
Version *-1.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.51% 0.71
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://plugins.trac.wordpress.org/changeset/2657583
Patch
Third Party Advisory
https://wpscan.com/vulnerability/3999a1b9-df85-43b1-b412-dc8a6f71cc5d
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/0f0f50e0-7015-4f00-880b-6eb94961177f
Third Party Advisory