Description
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-04T17:57:33.499Z
Reserved: 2023-08-09T02:20:30.651Z
Link: CVE-2023-40068
Updated: 2024-08-02T18:24:55.443Z
Status : Modified
Published: 2023-08-21T09:15:10.430
Modified: 2024-11-21T08:18:38.120
Link: CVE-2023-40068
No data.
OpenCVE Enrichment
No data.
Weaknesses