5.4
CVE-2022-4507
- EPSS 0.25%
- Veröffentlicht 16.01.2023 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:35:24
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Real Cookie Banner <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
Mögliche Gegenmaßnahme
Real Cookie Banner: GDPR & ePrivacy Cookie Consent: Update to version 3.4.10, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
Version
*-3.4.9
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devowl ≫ Wordpress Real Cookie Banner SwPlatformwordpress Version < 3.4.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.482 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|