The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Metrics
Affected Vendors & Products
References
History
Mon, 06 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 02 Jan 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
Title | AHAthat Plugin <= 1.6 - Reflected XSS via REQUEST_URI | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2025-01-02T06:00:13.479Z
Updated: 2025-01-06T20:26:50.598Z
Reserved: 2024-12-12T22:04:10.012Z
Link: CVE-2024-12595
Vulnrichment
Updated: 2025-01-06T20:26:23.443Z
NVD
Status : Awaiting Analysis
Published: 2025-01-02T06:15:07.983
Modified: 2025-01-06T21:15:14.003
Link: CVE-2024-12595
Redhat
No data.