CVE-2023-0603
Sloth Logo Customizer <= 2.0.2 - Stored XSS via CSRF
Vexday Risk Score
26Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 13.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
08 may 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
Unknown · Sloth Logo Customizer¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →