Security Advisory

CVE-2020-24316

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-08-26 13:09:23
Last updated 2024-08-04 15:12:08
Assigner mitre
State PUBLISHED

Description

WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.