← volver
CVE-2022-0648

Team Circle Image Slider With Lightbox < 1.0.16 - Reflected Cross-Site Scripting

EPSS 0.8%CWE-79
The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →