PT-2022-7928 · Bestwebsoft · Bestwebsoft Contact Form Plugin
Julien Rentrop
·
Published
2022-06-16
·
Updated
2022-06-28
·
CVE-2017-20055
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BestWebSoft Contact Form Plugin version 4.0.0
Description
A vulnerability has been found in the BestWebSoft Contact Form Plugin, allowing for basic cross site scripting (Stored) attacks. The manipulation can be initiated remotely. The issue affects an unknown part of the plugin.
Recommendations
For BestWebSoft Contact Form Plugin version 4.0.0, upgrade to version 4.0.2 to address this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bestwebsoft Contact Form Plugin