PT-2023-28047 · Unknown · Irina Sokolovskaya Goods Catalog
Abdi Pranata
·
Published
2023-09-29
·
Updated
2023-10-02
·
CVE-2023-41687
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Irina Sokolovskaya Goods Catalog plugin versions <= 2.4.1
Description
The issue is related to a Stored Cross-Site Scripting (XSS) vulnerability. It affects versions of the Irina Sokolovskaya Goods Catalog plugin where authentication as a contributor or higher is required to exploit.
Recommendations
For versions <= 2.4.1, update to a version higher than 2.4.1 to resolve the issue.
As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Irina Sokolovskaya Goods Catalog