OSV 1.4.0 · unreviewed · 修改于 2022-01-09 08:00
发布时间
2022-01-04 08:00
GitHub 审查时间
—
NVD 发布时间
2022-01-03 21:15
源文件
advisories/unreviewed/2022/01/GHSA-4p7m-87rg-hcph/GHSA-4p7m-87rg-hcph.json
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
该公告没有提供结构化的受影响软件包信息。