2023-11-30 15:00:22 +00:00
{
"id" : "CVE-2023-40674" ,
"sourceIdentifier" : "audit@patchstack.com" ,
"published" : "2023-11-30T13:15:07.740" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:19:56.947" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-11-30 15:00:22 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs \u2013 Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue affects Simple URLs \u2013 Link Cloaking, Product Displays, and Affiliate Link Management: from n/a through 118.\n\n"
2023-12-05 21:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "Neutralizaci\u00f3n inadecuada de la entrada durante la vulnerabilidad de generaci\u00f3n de p\u00e1ginas web ('Scripting entre sitios') en Lasso Simple URLs \u2013 Link Cloaking, Product Displays, and Affiliate Link Management permite almacenar XSS. Este problema afecta a Simple URLs \u2013 Link Cloaking, Product Displays, and Affiliate Link Management: desde n/a hasta 118."
2023-11-30 15:00:22 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-12-05 21:00:22 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "audit@patchstack.com" ,
"type" : "Secondary" ,
2023-12-05 21:00:22 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2023-12-05 21:00:22 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-12-05 21:00:22 +00:00
} ,
"exploitabilityScore" : 2.3 ,
2024-12-08 03:06:42 +00:00
"impactScore" : 3.7
2023-12-05 21:00:22 +00:00
} ,
2023-11-30 15:00:22 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-11-30 15:00:22 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM" ,
2023-11-30 15:00:22 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-11-30 15:00:22 +00:00
} ,
"exploitabilityScore" : 2.3 ,
2024-12-08 03:06:42 +00:00
"impactScore" : 2.7
2023-11-30 15:00:22 +00:00
}
]
} ,
"weaknesses" : [
{
"source" : "audit@patchstack.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-11-30 15:00:22 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
2023-12-05 21:00:22 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:getlasso:simple_urls:*:*:*:*:*:wordpress:*:*" ,
"versionEndIncluding" : "118" ,
"matchCriteriaId" : "BFD40A51-39E1-41AC-A24E-A0B50CC42D50"
}
]
}
]
}
] ,
2023-11-30 15:00:22 +00:00
"references" : [
{
"url" : "https://patchstack.com/database/vulnerability/simple-urls/wordpress-simple-urls-plugin-117-shortcode-cross-site-scripting-xss-vulnerability?_s_id=cve" ,
2023-12-05 21:00:22 +00:00
"source" : "audit@patchstack.com" ,
"tags" : [
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://patchstack.com/database/vulnerability/simple-urls/wordpress-simple-urls-plugin-117-shortcode-cross-site-scripting-xss-vulnerability?_s_id=cve" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-11-30 15:00:22 +00:00
}
]
}