2024-02-10 11:00:28 +00:00
{
"id" : "CVE-2023-51404" ,
"sourceIdentifier" : "audit@patchstack.com" ,
"published" : "2024-02-10T09:15:07.480" ,
2024-02-15 07:00:30 +00:00
"lastModified" : "2024-02-15T06:26:06.387" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-02-10 11:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My Agile Privacy \u2013 The only GDPR solution for WordPress that you can truly trust allows Stored XSS.This issue affects My Agile Privacy \u2013 The only GDPR solution for WordPress that you can truly trust: from n/a through 2.1.7.\n\n"
2024-02-15 07:00:30 +00:00
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de neutralizaci\u00f3n inadecuada de la entrada durante la generaci\u00f3n de p\u00e1ginas web ('Cross-site Scripting') en MyAgilePrivacy My Agile Privacy \u2013 The only GDPR solution for WordPress that you can truly trust permite Stored XSS. Este problema afecta a My Agile Privacy \u2013 The only GDPR solution for WordPress that you can truly trust: desde n/a hasta 2.1.7."
2024-02-10 11:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-02-15 07:00:30 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 2.7
} ,
2024-02-10 11:00:28 +00:00
{
"source" : "audit@patchstack.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 3.7
}
]
} ,
"weaknesses" : [
{
2024-02-15 07:00:30 +00:00
"source" : "nvd@nist.gov" ,
2024-02-10 11:00:28 +00:00
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
2024-02-15 07:00:30 +00:00
} ,
{
"source" : "audit@patchstack.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:myagileprivacy:my_agile_privacy:*:*:*:*:*:wordpress:*:*" ,
"versionEndIncluding" : "2.1.7" ,
"matchCriteriaId" : "D5725469-E6A9-45B8-BCEC-36243B9FD1E0"
}
]
}
]
2024-02-10 11:00:28 +00:00
}
] ,
"references" : [
{
"url" : "https://patchstack.com/database/vulnerability/myagileprivacy/wordpress-my-agile-privacy-plugin-2-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" ,
2024-02-15 07:00:30 +00:00
"source" : "audit@patchstack.com" ,
"tags" : [
"Third Party Advisory"
]
2024-02-10 11:00:28 +00:00
}
]
}