5 results (0.008 seconds)

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

06 Jun 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en Yannick Lefebvre Link Library link-library permite el XSS reflejado. Este problema afecta a la librería de enlaces: desde n/a hasta 7.6.3. The Link Li... • https://patchstack.com/database/vulnerability/link-library/wordpress-link-library-plugin-7-6-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

23 Dec 2022 — The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). El complemento Link Library de WordPress anterior a 7.4.1 no sanitiza ni escapa algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de cross site... • https://wpscan.com/vulnerability/c4688c0b-0538-4151-995c-d437d7e4829d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

30 Dec 2021 — The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack El plugin Link Library de WordPress versiones anteriores a 7.2.8, no presenta una comprobación de tipo CSRF cuando es restablecida la configuración de la biblioteca, permitiendo a atacantes hacer que un administrador conectado restablezca configuraciones arbitrarias por medio de un ataque de tipo CSRF • https://wpscan.com/vulnerability/1cd30913-67c7-46c3-a2de-dcca0c332323 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

30 Dec 2021 — The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting El plugin Link Library de WordPress versiones anteriores a 7.2.9, no sanea y escapa del parámetro settingscopy antes de devolverlo a una página de administración, conllevando a un ataque de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/96204946-0b10-4a2c-8079-473883ff95b6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

30 Dec 2021 — The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request El plugin Link Library de WordPress versiones anteriores a 7.2.8, no dispone de autorización cuando se eliminan enlaces, permitiendo a usuarios no autenticados eliminar enlaces arbitrarios por medio de una petición diseñada • https://wpscan.com/vulnerability/7a7603ce-d76d-4c49-a886-67653bed8cd3 • CWE-862: Missing Authorization •