CVE-2013-10020
MMDeveloper A Forms Plugin a-forms.php cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as problematic, was found in MMDeveloper A Forms Plugin up to 1.4.2 on WordPress. This affects an unknown part of the file a-forms.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The identifier of the patch is 3e693197bd69b7173cc16d8d2e0a7d501a2a0b06. It is recommended to upgrade the affected component. The identifier VDB-222609 was assigned to this vulnerability.
Es wurde eine problematische Schwachstelle in MMDeveloper A Forms Plugin bis 1.4.2 für WordPress gefunden. Betroffen hiervon ist ein unbekannter Ablauf der Datei a-forms.php. Mit der Manipulation mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Ein Aktualisieren auf die Version 1.4.3 vermag dieses Problem zu lösen. Der Patch wird als 3e693197bd69b7173cc16d8d2e0a7d501a2a0b06 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
The A Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-08-19 CVE Published
- 2023-03-08 CVE Reserved
- 2024-08-06 CVE Updated
- 2024-09-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.222609 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/wp-plugins/a-forms/commit/3e693197bd69b7173cc16d8d2e0a7d501a2a0b06 | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
A-forms Project Search vendor "A-forms Project" | A-forms Search vendor "A-forms Project" for product "A-forms" | < 1.4.3 Search vendor "A-forms Project" for product "A-forms" and version " < 1.4.3" | wordpress |
Affected
|