← volver
CVE-2023-0603

Sloth Logo Customizer <= 2.0.2 - Stored XSS via CSRF

CVSS 8.8 HIGHEPSS 13.9%
Vexday Risk Score
26Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 13.9%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
08 may 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →