"-Synchronized-Data."

This commit is contained in:
CVE Team 2023-02-27 10:00:34 +00:00
parent fe698e2f0d
commit 8870a53b04
No known key found for this signature in database
GPG Key ID: E3252B3D49582C98
2 changed files with 13 additions and 4 deletions

View File

@ -11,7 +11,7 @@
"description_data": [
{
"lang": "eng",
"value": "The Flat PM WordPress plugin through 2.661 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks."
"value": "The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin"
}
]
},
@ -35,12 +35,13 @@
"product": {
"product_data": [
{
"product_name": "Flat PM",
"product_name": "FlatPM",
"version": {
"version_data": [
{
"version_value": "0",
"version_affected": "="
"version_affected": "<",
"version_name": "0",
"version_value": "3.0.13"
}
]
}
@ -70,6 +71,10 @@
{
"lang": "en",
"value": "cydave"
},
{
"lang": "en",
"value": "WPScan"
}
]
}

View File

@ -77,6 +77,10 @@
{
"lang": "en",
"value": "Son Tran from VNPT - VCI"
},
{
"lang": "en",
"value": "kuteminh11"
}
]
}