Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zack Tollman

#52997of 53,639
3.3Total CVSS
Vulnerabilities · 1
PT-2023-10273
3.3
2023-03-06
Fastly · Fastly Plugin · CVE-2015-10094
**Name of the Vulnerable Software and Affected Versions** Fastly Plugin versions up to 0.97 **Description** A vulnerability was found in the Fastly Plugin, which has been rated as problematic. The issue affects the function post of the file lib/api.php. The manipulation of the `url` argument leads to cross-site scripting. The attack may be launched remotely. **Recommendations** To address this issue, upgrade to version 0.98. As a temporary workaround, consider restricting the use of the `post` function in the lib/api.php file until the update is applied. Additionally, avoid using the `url` argument in the affected function to minimize the risk of exploitation.