6.1

CVE-2023-4294

Exploit

URL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer header

URL Shortify <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting via Referrer Header

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.
Mögliche Gegenmaßnahme
URL Shortify – Simple and Easy URL Shortener: Update to version 1.7.6, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KaizencodersUrl Shortify SwPlatformwordpress Version < 1.7.6
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt URL Shortify – Simple and Easy URL Shortener
Version *-1.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.496
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/1fc71fc7-861a-46cc-a147-1c7ece9a7776
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/7b452283-9f0d-469b-b1b8-4bd253f9ea1d
Third Party Advisory