2 results (0.006 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter. WP Mailster versión 1.6.18.0, permite un ataque de tipo XSS cuando una víctima abre los detalles de un servidor de correo en la página mst_servers, por un parámetro server_host, server_name o connection_parameter diseñado • https://www.compass-security.com/en/research/advisories https://www.compass-security.com/fileadmin/Research/Advisories/2021-18_CSNC-2021-018-WPMailster_XSS_CSRF.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php. El plugin WP Mailster en versiones anteriores a la 1.5.5 para WordPress contiene XSS en el manipulador unsubscribe mediante el parámetro mes en view/subscription/unsubscribe2.php. The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mes' parameter found in the 'view/subscription/unsubscribe2.php' file in versions up to 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://packetstormsecurity.com/files/145222/WordPress-WP-Mailster-1.5.4.0-Cross-Site-Scripting.html https://wordpress.org/plugins/wp-mailster/#developers https://wpvulndb.com/vulnerabilities/8973 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •