PT-2014-6013 · WordPress · Wp Ultimate Email Marketer
Prajal Kulkarni
·
Publicado
2014-07-02
·
Atualizado
2014-07-09
·
CVE-2014-4600
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WP Ultimate Email Marketer plugin versions 1.1.0 and earlier
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The vulnerable parameters are the
listname and contact parameters in the contact/edit.php file.Recommendations
For WP Ultimate Email Marketer plugin versions 1.1.0 and earlier, update to a version later than 1.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the contact/edit.php file to minimize the risk of exploitation. Avoid using the
listname and contact parameters in the affected file until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Ultimate Email Marketer