7.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
WordPress OpenID plugin <= 3.6.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DiSo Development Team OpenID allows Reflected XSS.This issue affects OpenID: from n/a through 3.6.1.
References
Affected products
- =<3.6.1
Matching in nixpkgs
pkgs.luaPackages.lua-resty-openidc
A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality
-
nixos-unstable -
- nixpkgs-unstable 1.8.0-1
pkgs.python312Packages.flask-openid
OpenID support for Flask
-
nixos-unstable -
- nixpkgs-unstable 1.3.1
pkgs.python313Packages.flask-openid
OpenID support for Flask
-
nixos-unstable -
- nixpkgs-unstable 1.3.1
pkgs.lua51Packages.lua-resty-openidc
A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality
-
nixos-unstable -
- nixpkgs-unstable 1.8.0-1
pkgs.lua52Packages.lua-resty-openidc
A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality
-
nixos-unstable -
- nixpkgs-unstable 1.8.0-1
pkgs.lua53Packages.lua-resty-openidc
A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality
-
nixos-unstable -
- nixpkgs-unstable 1.8.0-1
pkgs.lua54Packages.lua-resty-openidc
A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality
-
nixos-unstable -
- nixpkgs-unstable 1.8.0-1
pkgs.luajitPackages.lua-resty-openidc
A library for NGINX implementing the OpenID Connect Relying Party (RP) and the OAuth 2.0 Resource Server (RS) functionality
-
nixos-unstable -
- nixpkgs-unstable 1.8.0-1
pkgs.python312Packages.openidc-client
CLI python OpenID Connect client with token caching and management
-
nixos-unstable -
- nixpkgs-unstable 0.6.0
pkgs.python312Packages.python3-openid
OpenID support for modern servers and consumers
-
nixos-unstable -
- nixpkgs-unstable python3-openid-3.2.0
pkgs.python313Packages.openidc-client
CLI python OpenID Connect client with token caching and management
-
nixos-unstable -
- nixpkgs-unstable 0.6.0
pkgs.python313Packages.python3-openid
OpenID support for modern servers and consumers
-
nixos-unstable -
- nixpkgs-unstable python3-openid-3.2.0
Package maintainers
-
@disassembler Samuel Leathers <disasm@gmail.com>