PT-2023-3547 · Unknown · Eelv Newsletter Plugin
Published
2023-06-04
·
Updated
2024-05-17
·
CVE-2013-10028
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
EELV Newsletter Plugin versions 2.x
Description
The issue exists due to inadequate protection of the web page structure in the
style newsletter function of the lettreinfo.php file. This can be exploited by a remote attacker to conduct cross-site scripting attacks by manipulating the email argument. The attack may be launched remotely.Recommendations
For EELV Newsletter Plugin version 2.x, it is recommended to upgrade the affected component to a version that includes the patch 3339b42316c5edf73e56eb209b6a3bb3e868d6ed. As a temporary workaround, consider restricting access to the
style newsletter function in the lettreinfo.php file until a patch is available. Avoid using the email argument in the affected function until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eelv Newsletter Plugin