Description
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:10:41.628Z
Reserved: 2019-09-15T00:00:00.000Z
Link: CVE-2019-16332
No data.
Status : Modified
Published: 2019-09-15T22:15:10.370
Modified: 2024-11-21T04:30:32.113
Link: CVE-2019-16332
No data.
OpenCVE Enrichment
No data.
Weaknesses