Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-3511 | 1 Getawesomesupport | 1 Awesome Support | 2022-11-29 | N/A | 6.5 MEDIUM |
The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector | |||||
CVE-2022-38073 | 1 Getawesomesupport | 1 Awesome Support | 2022-09-22 | N/A | 5.4 MEDIUM |
Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress. | |||||
CVE-2021-36919 | 1 Getawesomesupport | 1 Awesome Support | 2021-12-02 | 3.5 LOW | 5.4 MEDIUM |
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee). | |||||
CVE-2019-20181 | 1 Getawesomesupport | 1 Awesome Support | 2020-01-14 | 3.5 LOW | 4.8 MEDIUM |
The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter. | |||||
CVE-2015-9318 | 1 Getawesomesupport | 1 Awesome Support | 2019-08-22 | 5.0 MEDIUM | 7.5 HIGH |
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. | |||||
CVE-2015-9317 | 1 Getawesomesupport | 1 Awesome Support | 2019-08-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages. |