Security Advisory

CVE-2014-4528

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-07-01 14:00:00
Last updated 2024-08-06 11:20:26
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotion Generator (fbpromotions) plugin 1.3.4 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) promo_type, (2) fb_edit_action, or (3) promo_id parameter.