PT-2020-15901 · Blubrry · Blubrry Subscribe-Sidebar Plugin
Published
2020-08-31
·
Updated
2024-02-14
·
CVE-2020-25033
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Blubrry subscribe-sidebar plugin version 1.3.1
Description
The issue allows for reflected XSS in the subscribe-sidebar.php file. This can be exploited through the
status parameter.Recommendations
For version 1.3.1, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the subscribe-sidebar.php file to minimize the risk of exploitation. Avoid using the
status parameter in the affected endpoint until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blubrry Subscribe-Sidebar Plugin