Dismissed
(not in Nixpkgs)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.
References
-
https://wpscan.com/vulnerability/d3a37071-5fb1-4aa2-8f89-eb13c46f6126/ technical-descriptionvdb-entryexploit
Affected products
Divi
- <5.9.0
Matching in nixpkgs
pkgs.midivisualizer
Small MIDI visualizer tool, using OpenGL
pkgs.pkgsRocm.midivisualizer
Small MIDI visualizer tool, using OpenGL
pkgs.typstPackages.divine-words
None
pkgs.typstPackages.divine-words_0_1_0
None
Package maintainers
-
@ericdallo Eric Dallo <ercdll1337@gmail.com>