Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) xyz_em_campName to admin/create_campaign.php or (2) admin/edit_campaign.php, (3) xyz_em_email parameter to admin/edit_email.php, (4) xyz_em_exportbatchSize parameter to import_export.php, or (5) pagination limit in the Newsletter Manager options.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-01-16T21:00:00Z
Updated: 2024-09-16T20:22:57.378Z
Reserved: 2014-01-16T00:00:00Z
Link: CVE-2012-6628
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-01-16T21:55:44.787
Modified: 2024-11-21T01:46:33.310
Link: CVE-2012-6628
Redhat
No data.