PT-2023-6578 · WordPress · Ninja Forms Contact Form
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ninja Forms Contact Form WordPress plugin versions prior to 3.6.22
Description
The issue is related to the lack of protection of the web page structure, allowing for reflected cross-site scripting attacks. This could enable a remote attacker to conduct inter-site script attacks. The vulnerability arises from the improper escaping of user input before it is outputted back in an admin page, which could be used against high-privilege users such as administrators.
Recommendations
For versions prior to 3.6.22, update to version 3.6.22 or later to resolve the issue. As a temporary workaround, consider restricting access to admin pages to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ninja Forms Contact Form