PT-2019-7253 · WordPress · All-In-One-Wp-Security-And-Firewall

Publicado

2019-08-13

·

Atualizado

2019-08-16

·

CVE-2015-9294

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions all-in-one-wp-security-and-firewall plugin versions prior to 3.9.5
Description The issue concerns a cross-site scripting (XSS) problem in the add query arg and remove query arg function instances. This could potentially allow attackers to inject malicious scripts into websites using the all-in-one-wp-security-and-firewall plugin for WordPress.
Recommendations For versions prior to 3.9.5, update to version 3.9.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the add query arg and remove query arg functions until the update is applied.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-9294

Produtos afetados

All-In-One-Wp-Security-And-Firewall