2024-12-08 03:06:42 +00:00

52 lines
1.9 KiB
JSON

{
"id": "CVE-2024-2836",
"sourceIdentifier": "contact@wpscan.com",
"published": "2024-04-15T05:15:15.267",
"lastModified": "2024-11-21T09:10:38.530",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed"
},
{
"lang": "es",
"value": "El complemento Social Share, Social Login and Social Comments Plugin de WordPress anterior a 7.13.64 no sanitiza ni escapa a algunas de sus configuraciones, lo que podr\u00eda permitir a usuarios con altos privilegios, como editores, realizar ataques de cross-site scripting incluso cuando unfiltered_html no est\u00e1 permitido."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.7,
"impactScore": 2.7
}
]
},
"references": [
{
"url": "https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/",
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}