The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dylanjames
Dylanjames zephyr Project Manager |
|
CPEs | cpe:2.3:a:dylanjames:zephyr_project_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dylanjames
Dylanjames zephyr Project Manager |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-30T06:00:10.760Z
Updated: 2024-11-04T16:38:26.463Z
Reserved: 2024-07-05T20:00:20.656Z
Link: CVE-2024-6536
Vulnrichment
Updated: 2024-08-01T21:41:03.512Z
NVD
Status : Awaiting Analysis
Published: 2024-07-30T06:15:04.013
Modified: 2024-11-21T09:49:50.537
Link: CVE-2024-6536
Redhat
No data.