PT-2023-3547 · Unknown · Eelv Newsletter Plugin

CVE-2013-10028

·

Publicado

2023-06-04

·

Atualizado

2024-05-17

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions EELV Newsletter Plugin versions 2.x
Description The issue exists due to inadequate protection of the web page structure in the style newsletter function of the lettreinfo.php file. This can be exploited by a remote attacker to conduct cross-site scripting attacks by manipulating the email argument. The attack may be launched remotely.
Recommendations For EELV Newsletter Plugin version 2.x, it is recommended to upgrade the affected component to a version that includes the patch 3339b42316c5edf73e56eb209b6a3bb3e868d6ed. As a temporary workaround, consider restricting access to the style newsletter function in the lettreinfo.php file until a patch is available. Avoid using the email argument in the affected function until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03762
CVE-2013-10028

Produtos afetados

Eelv Newsletter Plugin