CVE-2024-51897 – News Articles <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2024-51897
The News Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-1000515
https://notcve.org/view.php?id=CVE-2018-1000515
ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server.. ventrian News-Articles en la versión NewsArticles.00.09.11 contiene una vulnerabilidad de XEE (XML External Entity) en News-Articles/API/MetaWebLog/Handler.ashx.vb que puede resultar en que un atacante lea cualquier archivo en el servidor o emplee ataques smbrelay para acceder al servidor. • https://drive.google.com/drive/folders/1P7djpYX8VQ0oplhOCMFNdKQByCcw2ncU?usp=sharing • CWE-611: Improper Restriction of XML External Entity Reference •