CVE-2022-27231
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
Affected (1)
Products: Veronalabs: Wp Statistics
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 13.2.0 |
References (6)
Source: vultures@jpcert.or.jp
Release NotesThird Party Advisory
Source: vultures@jpcert.or.jp
ProductThird Party Advisory
Source: vultures@jpcert.or.jp
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Timeline
No history available yet.