2024-12-08 03:06:42 +00:00

52 lines
1.8 KiB
JSON

{
"id": "CVE-2024-4096",
"sourceIdentifier": "contact@wpscan.com",
"published": "2024-07-30T06:15:02.723",
"lastModified": "2024-11-21T09:42:11.190",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks"
},
{
"lang": "es",
"value": "El complemento Responsive Tabs de WordPress hasta la versi\u00f3n 4.0.8 no sanitiza ni escapa a algunas de sus configuraciones de pesta\u00f1as, lo que podr\u00eda permitir a usuarios con altos privilegios, como Colaboradores y superiores, realizar ataques de Cross Site Scripting almacenado."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 1.7,
"impactScore": 3.7
}
]
},
"references": [
{
"url": "https://wpscan.com/vulnerability/4dba5e9e-24be-458a-9150-7c7a958e66cb/",
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/4dba5e9e-24be-458a-9150-7c7a958e66cb/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}