The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-07-17T13:30:00.715Z
Updated: 2024-10-30T13:59:16.682Z
Reserved: 2023-05-15T09:55:25.578Z
Link: CVE-2023-2701
Vulnrichment
Updated: 2024-08-02T06:33:05.309Z
NVD
Status : Modified
Published: 2023-07-17T14:15:10.097
Modified: 2023-11-07T04:13:11.413
Link: CVE-2023-2701
Redhat
No data.