PT-2023-10273 · Fastly · Fastly Plugin

Zack Tollman

·

Publicado

2023-03-06

·

Atualizado

2024-05-17

·

CVE-2015-10094

CVSS v2.0

3.3

Baixa

VetorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fastly Plugin versions up to 0.97
Description A vulnerability was found in the Fastly Plugin, which has been rated as problematic. The issue affects the function post of the file lib/api.php. The manipulation of the url argument leads to cross-site scripting. The attack may be launched remotely.
Recommendations To address this issue, upgrade to version 0.98. As a temporary workaround, consider restricting the use of the post function in the lib/api.php file until the update is applied. Additionally, avoid using the url argument in the affected function to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10094

Produtos afetados

Fastly Plugin