7.1
CVE-2024-1983
- EPSS 0.18%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 05.05.2025 18:38:46
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS
Simple Ajax Chat <= 20240216 - Unauthenticated Stored Cross-Site Scripting
The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.
Mögliche Gegenmaßnahme
Simple Ajax Chat – Add a Fast, Secure Chat Box: Update to version 20240223, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plugin-planet ≫ Simple Ajax Chat SwPlatformwordpress Version < 20240223
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Simple Ajax Chat – Add a Fast, Secure Chat Box
Version
*-20240216
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.399 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.1 | 2.8 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
|