PT-2023-10628 · Unknown · Wangguard Plugin

CVE-2017-20177

·

Published

2023-02-06

·

Updated

2024-05-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WangGuard Plugin version 1.8.0
Description A problematic issue has been found in the WangGuard Plugin, affecting the wangguard users info function of the wangguard-user-info.php file in the WGG User List Handler component. The manipulation of the userIP argument leads to cross-site scripting. The attack can be launched remotely.
Recommendations For WangGuard Plugin version 1.8.0, apply a patch to fix this issue. As a temporary workaround, consider restricting the use of the wangguard users info function until a patch is available. Avoid using the userIP argument in the affected component to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20177

Affected Products

Wangguard Plugin