PT-2023-18645 · Unknown · Wpmobile.App
István Márton
+1
·
Published
2023-03-23
·
Updated
2023-03-28
·
CVE-2023-22702
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WPMobile.App versions <= 11.13
Description
A Cross-Site Scripting (XSS) vulnerability has been discovered in the WPMobile.App plugin for Android and iOS mobile applications, affecting versions up to and including 11.13. This issue allows for XSS attacks when authentication is set to contributor or higher.
Recommendations
For versions <= 11.13, update to a version higher than 11.13 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpmobile.App