Beveiligingsadvies

CVE-2018-11485

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-06-01 15:00:00
Laatst bijgewerkt 2024-08-05 08:10:14
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.