The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-30T15:05:57.264Z
Reserved: 2023-05-08T13:04:37.391Z
Link: CVE-2023-2579
Updated: 2024-08-02T06:26:09.687Z
Status : Modified
Published: 2023-07-17T14:15:09.970
Modified: 2024-11-21T07:58:52.127
Link: CVE-2023-2579
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.