The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/b1aef75d-0c84-4702-83fc-11f0e98a0821 | Exploit Third Party Advisory |
Configurations
Information
Published : 2023-01-09 15:15
Updated : 2023-01-12 22:35
NVD link : CVE-2022-4310
Mitre link : CVE-2022-4310
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
wp-slimstat
- slimstat_analytics