Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
History

Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2023-08-21T08:13:50.271Z

Updated: 2024-10-04T17:57:33.499Z

Reserved: 2023-08-09T02:20:30.651Z

Link: CVE-2023-40068

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:55.443Z

cve-icon NVD

Status : Modified

Published: 2023-08-21T09:15:10.430

Modified: 2024-11-21T08:18:38.120

Link: CVE-2023-40068

cve-icon Redhat

No data.