PT-2023-6577 · WordPress · Custom 404 Pro
Chien Vuong
·
Publicado
2023-05-03
·
Atualizado
2025-01-09
·
CVE-2023-2023
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Custom 404 Pro versions prior to 3.7.3
Description
The issue is related to the Custom 404 Pro WordPress plugin, which does not properly escape some URLs before outputting them in attributes. This can lead to Reflected Cross-Site Scripting, allowing a remote attacker to conduct inter-site script attacks.
Recommendations
For versions prior to 3.7.3, update to version 3.7.3 or later to resolve the issue.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Custom 404 Pro