CVE编号 | CVE-2024-12460 |
---|---|
发布日期 | 2025-03-08T02:24:02.760Z |
更新日期 | 2025-03-10T16:04:53.958Z |
状态 | PUBLISHED |
受影响的供应商 | laurencebahiirwa |
受影响的产品 | Years Since – Timeless Texts |
描述 | The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
参考链接: