PT-2023-30602 · Automattic · Woocommerce Blocks+1

Rafie Muhammad

·

Publicado

2023-11-30

·

Atualizado

2023-12-05

·

CVE-2023-47777

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WooCommerce versions through 8.1.1 WooCommerce Blocks versions through 11.1.1
Description The issue affects Automattic WooCommerce and Automattic WooCommerce Blocks, allowing Stored XSS due to improper neutralization of input during web page generation. This is a Cross-site Scripting vulnerability.
Recommendations For WooCommerce versions through 8.1.1, update to a version later than 8.1.1 to resolve the issue. For WooCommerce Blocks versions through 11.1.1, update to a version later than 11.1.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the web application to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-47777

Produtos afetados

Woocommerce
Woocommerce Blocks