5.4
CVE-2023-40068
- EPSS 24.67%
- Published 21.08.2023 09:15:10
- Last modified 21.11.2024 08:18:38
- Source vultures@jpcert.or.jp
- Teams watchlist Login
- Open Login
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
Data is provided by the National Vulnerability Database (NVD)
Advancedcustomfields ≫ Advanced Custom Fields SwEdition- SwPlatformwordpress Version >= 6.1.0 <= 6.1.7
Advancedcustomfields ≫ Advanced Custom Fields SwEditionpro SwPlatformwordpress Version >= 6.1.0 <= 6.1.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 24.67% | 0.959 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.