6.1
CVE-2023-0602
- EPSS 5.65%
- Veröffentlicht 31.07.2023 10:15:10
- Zuletzt bearbeitet 21.11.2024 07:37:28
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Twittee Text Tweet <= 1.0.8 - Reflected Cross-Site Scripting
The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.
Mögliche Gegenmaßnahme
Twittee Text Tweet: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Twittee Text Tweet
Version
*-1.0.8
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Johnniejodelljr ≫ Twittee Text Tweet SwPlatformwordpress Version <= 1.0.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.65% | 0.9 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|