// For flags

CVE-2019-17515

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 - Reflected Cross-Site Scripting

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.

El plugin CleanTalk cleantalk-spam-protect versiones anteriores a la versión 5.127.4 para WordPress, está afectado por: Cross Site Scripting (XSS). El impacto es: permite a un atacante ejecutar código arbitrario HTML y JavaScript por medio del parámetro from o till. El componente es: los archivos inc/cleantalk-users.php y inc/cleantalk-comments.php. El vector de ataque es: cuando el administrador inicia sesión, un ataque de tipo XSS reflejado puede ser ejecutado tras un clic en una URL maliciosa.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-10-12 CVE Reserved
  • 2019-11-12 CVE Published
  • 2023-09-17 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cleantalk
Search vendor "Cleantalk"
Spam Protection\, Antispam\, Firewall
Search vendor "Cleantalk" for product "Spam Protection\, Antispam\, Firewall"
< 5.127.4
Search vendor "Cleantalk" for product "Spam Protection\, Antispam\, Firewall" and version " < 5.127.4"
wordpress
Affected