PT-2019-7255 · WordPress · Download Monitor
Publicado
2019-08-13
·
Atualizado
2019-08-16
·
CVE-2015-9296
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
download-monitor plugin versions prior to 1.7.1
Description
The issue is related to a Cross-Site Scripting (XSS) vulnerability. It affects the
add query arg function. No information is provided about the estimated number of potentially affected devices or real-world incidents.Recommendations
For versions prior to 1.7.1, update to version 1.7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
add query arg function until the update is applied.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Download Monitor