ZeroHour

CVE-2023-0421

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p42
Published
()
Modified
Description

The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it in an admin panel, allowing unauthenticated attackers to trick a logged in admin to trigger a XSS payload by clicking a link.

Vendors
cloud manager project
Products
cloud manager
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.