发布时间: 2023年2月6日
修改时间: 2023年2月6日
The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
NVD | openEuler | |
---|---|---|
Confidentiality | Low | Low |
Attack Vector | Network | Network |
CVSS评分 | 5.4 | 5.4 |
Attack Complexity | Low | Low |
Privileges Required | Low | Low |
Scope | Changed | Changed |
Integrity | Low | Low |
User Interaction | Required | Required |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1035 | The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | 2023年2月6日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | fontawesome-fonts | Unaffected |
KY3.4-5 | fontawesome-fonts | Unaffected |
KY3.5.1 | fontawesome-fonts | Unaffected |
KY3.5.2 | fontawesome-fonts | Unaffected |