CVE-2015-1879
Google Doc Embedder <= 2.5.18 - Cross-Site Scripting
Severity Score
5.4
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php.
Vulnerabilidad de XSS en el plugin Google Doc Embedder anterior a 2.5.19 para WordPress permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través del parámetro profile en una acción de editar en la página gde-settings en wp-admin/options-general.php.
*Credits:
Kenneth Jepsen,Mikkel Vej,Morten Nortoft
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-01-26 CVE Published
- 2015-02-19 CVE Reserved
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/72547 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/130309/WordPress-Google-Doc-Embedder-2.5.18-Cross-Site-Scripting.html | 2024-09-17 |
URL | Date | SRC |
---|---|---|
https://wordpress.org/plugins/google-document-embedder/changelog | 2015-02-20 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Doc Embedder Search vendor "Google Doc Embedder" | Google Doc Embedder Search vendor "Google Doc Embedder" for product "Google Doc Embedder" | 2.5.18 Search vendor "Google Doc Embedder" for product "Google Doc Embedder" and version "2.5.18" | wordpress |
Affected
|