Description
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12888 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins. |
References
History
Tue, 04 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-04T18:41:37.250Z
Reserved: 2023-02-17T21:41:10.218Z
Link: CVE-2023-0899
Updated: 2024-08-02T05:24:34.694Z
Status : Modified
Published: 2023-04-24T19:15:09.033
Modified: 2025-02-04T19:15:27.287
Link: CVE-2023-0899
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD