PT-2023-3547 · Unknown · Eelv Newsletter Plugin

Published

2023-06-04

·

Updated

2024-05-17

·

CVE-2013-10028

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions EELV Newsletter Plugin versions 2.x
Description The issue exists due to inadequate protection of the web page structure in the style newsletter function of the lettreinfo.php file. This can be exploited by a remote attacker to conduct cross-site scripting attacks by manipulating the email argument. The attack may be launched remotely.
Recommendations For EELV Newsletter Plugin version 2.x, it is recommended to upgrade the affected component to a version that includes the patch 3339b42316c5edf73e56eb209b6a3bb3e868d6ed. As a temporary workaround, consider restricting access to the style newsletter function in the lettreinfo.php file until a patch is available. Avoid using the email argument in the affected function until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-03762
CVE-2013-10028

Affected Products

Eelv Newsletter Plugin