6.1
CVSSv3

CVE-2023-0421

Published: 08/05/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Cloud Manager WordPress plugin up to and including 1.0 does not sanitise and escape the query param ricerca before outputting it in an admin panel, allowing unauthenticated malicious users to trick a logged in admin to trigger a XSS payload by clicking a link.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloud manager project cloud manager