ZeroHour

CVE-2023-0285

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p39
Published
()
Modified
Description

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

Vendors
devowl
Products
real media library
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.