mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-12 02:04:49 +00:00
24 lines
950 B
JSON
24 lines
950 B
JSON
{
|
|
"id": "CVE-2023-7085",
|
|
"sourceIdentifier": "contact@wpscan.com",
|
|
"published": "2024-03-18T19:15:06.160",
|
|
"lastModified": "2024-03-18T19:40:00.173",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "El complemento Scalable Vector Graphics (SVG) de WordPress hasta la versi\u00f3n 3.4 no sanitiza los archivos SVG cargados, lo que podr\u00eda permitir a los usuarios con un rol tan bajo como Autor cargar un SVG malicioso que contenga payloads XSS."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"references": [
|
|
{
|
|
"url": "https://wpscan.com/vulnerability/a2ec1308-75a0-49d0-9288-33c6d9ee4328/",
|
|
"source": "contact@wpscan.com"
|
|
}
|
|
]
|
|
} |