← back
CVE-2022-4310

Slimstat Analytics < 4.9.3 - Unauthenticated Stored XSS

CVSS 6.1 MEDIUMEPSS 0.6%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Jan 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N