JH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
18Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendepss 2.0%
probabilidade de exploração
2.0%top 21% das CVEs
exploração observada
nãonenhuma fonte reporta
The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
Produtos afetados
Unknown · JH 404 Logger