2 results (0.002 seconds)

CVSS: 6.4EPSS: %CPEs: 1EXPL: 0

The News Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server.. ventrian News-Articles en la versión NewsArticles.00.09.11 contiene una vulnerabilidad de XEE (XML External Entity) en News-Articles/API/MetaWebLog/Handler.ashx.vb que puede resultar en que un atacante lea cualquier archivo en el servidor o emplee ataques smbrelay para acceder al servidor. • https://drive.google.com/drive/folders/1P7djpYX8VQ0oplhOCMFNdKQByCcw2ncU?usp=sharing • CWE-611: Improper Restriction of XML External Entity Reference •