Beveiligingsadvies

CVE-2023-0937

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-03-20 15:52:18
Laatst bijgewerkt 2025-02-25 21:17:38
Toegewezen door WPScan
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers