CVE-2023-0285

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:devowl:real_media_library:*:*:*:*:*:wordpress:*:*

Information

Published : 2023-02-21 01:15

Updated : 2023-02-27 17:54


NVD link : CVE-2023-0285

Mitre link : CVE-2023-0285


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

devowl

  • real_media_library