Description
The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Stored Cross-Site Scripting which could be used against admins when viewing submissions submitted through the Email Quote Form.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12968 | The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Stored Cross-Site Scripting which could be used against admins when viewing submissions submitted through the Email Quote Form. |
References
History
Tue, 11 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-11T21:22:59.113Z
Reserved: 2023-02-23T11:47:59.782Z
Link: CVE-2023-0983
Updated: 2024-08-02T05:32:45.990Z
Status : Modified
Published: 2023-04-10T14:15:08.677
Modified: 2025-02-11T22:15:24.950
Link: CVE-2023-0983
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD