The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Brevo
Brevo newsletter\, Smtp\, Email Marketing And Subscribe
CPEs cpe:2.3:a:sendinblue:newsletter\,_smtp\,_email_marketing_and_subscribe:*:*:*:*:*:wordpress:*:* cpe:2.3:a:brevo:newsletter\,_smtp\,_email_marketing_and_subscribe:*:*:*:*:*:wordpress:*:*
Vendors & Products Sendinblue
Sendinblue newsletter\, Smtp\, Email Marketing And Subscribe
Brevo
Brevo newsletter\, Smtp\, Email Marketing And Subscribe

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-01-08T15:37:01.843Z

Reserved: 2023-05-02T11:37:40.456Z

Link: CVE-2023-2472

cve-icon Vulnrichment

Updated: 2024-08-02T06:26:08.951Z

cve-icon NVD

Status : Modified

Published: 2023-06-05T14:15:10.110

Modified: 2025-01-08T16:15:28.610

Link: CVE-2023-2472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.