PT-2023-3547 · Unknown · Eelv Newsletter Plugin
CVE-2013-10028
·
Publicado
2023-06-04
·
Atualizado
2024-05-17
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
EELV Newsletter Plugin versions 2.x
Description
The issue exists due to inadequate protection of the web page structure in the
style newsletter function of the lettreinfo.php file. This can be exploited by a remote attacker to conduct cross-site scripting attacks by manipulating the email argument. The attack may be launched remotely.Recommendations
For EELV Newsletter Plugin version 2.x, it is recommended to upgrade the affected component to a version that includes the patch 3339b42316c5edf73e56eb209b6a3bb3e868d6ed. As a temporary workaround, consider restricting access to the
style newsletter function in the lettreinfo.php file until a patch is available. Avoid using the email argument in the affected function until the issue is resolved.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eelv Newsletter Plugin