PT-2019-6524 · WordPress · Google Analyticator
Published
2019-08-22
·
Updated
2019-08-26
·
CVE-2009-5158
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
google-analyticator plugin versions prior to 5.2.1 for WordPress
Description
The issue is related to insufficient HTML sanitization for Google Analytics API text. This could potentially allow for malicious activities due to the lack of proper input validation.
Recommendations
For versions prior to 5.2.1, update to version 5.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Google Analytics API text input fields until the update is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Analyticator