Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Umcms

#43204de 53,633
6.1CVSS total
Vulnerabilidades · 1
PT-2019-8534
6.1
2019-09-10
WordPress · Postman-Smtp · CVE-2017-18603
**Name of the Vulnerable Software and Affected Versions** postman-smtp plugin through 2017-10-04 for WordPress **Description** The issue concerns a cross-site scripting (XSS) problem. It is exploited via the `page` parameter in the "wp-admin/tools.php" page, specifically when accessing the postman email log. **Recommendations** For the postman-smtp plugin through 2017-10-04, consider disabling access to the wp-admin/tools.php?page=postman email log page until a fix is available. Restrict the use of the `page` parameter in this context to minimize the risk of exploitation.