Description


A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgrading to version 1.2.5 is able to address this issue. It is recommended to upgrade the affected component.

References


http://seclists.org/fulldisclosure/2017/Feb/81

ExploitMailing ListPatchThird Party Advisory

https://vuldb.com/?id.97373

Third Party Advisory

Weaknesses



CWE-79


CWE-80

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

5.4 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-06-24T07:15:07.310

3 years ago

Last modified

2022-06-30T15:18:04.983

3 years ago