PT-2023-10273 · Fastly · Fastly Plugin
Zack Tollman
·
Published
2023-03-06
·
Updated
2024-05-17
·
CVE-2015-10094
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Fastly Plugin versions up to 0.97
Description
A vulnerability was found in the Fastly Plugin, which has been rated as problematic. The issue affects the function post of the file lib/api.php. The manipulation of the
url argument leads to cross-site scripting. The attack may be launched remotely.Recommendations
To address this issue, upgrade to version 0.98. As a temporary workaround, consider restricting the use of the
post function in the lib/api.php file until the update is applied. Additionally, avoid using the url argument in the affected function to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastly Plugin