6.1 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
References
Affected products
- =<2.2.38
- =<3.0.5
- =<1.13.15
- =<2.4.2
- =<1.0.40
- =<1.4.0
- =<1.8.5
- =<1.9.0
- =<2.07
- =<1.7
- =<1.9.0
- =<1.1.16
- =<2.7.0
- =<2.3.1
- =<1.5.5
- =<1.4.2
- =<2.4.27
- =<2.9.7
- =<3.3.0
- =<1.0.4
- =<2.0.2
- =<2.6.0
- =<2.3.4
- =<2.5.5
- =<6.1.10
- =<3.9.6
- =<2.2.2
- =<3.2.4.4
- =<1.6.6
- =<1.2.56
- =<3.12
- =<1.6.0
- =<3.1.26
- =<1.2.6
- =<2.1.5
- =<1.4.7
- =<4.2.0
- =<4.4.1
- =<1.6.22
- =<1.3.1
- =<1.9.2
- =<1.7.34
- =<1.5.140
- =<2.8.4
- =<1.6.3.2
- =<5.3.4
- =<1.8.4.8.1
- =<2.1.6
- =<3.2.4
- =<3.5.1
- =<6.0.2
- =<1.5.8
- =<1.9.4
- =<1.6.0
- =<5.5.8
- =<3.7.3
- =<1.7
- =<2.0.0
- =<1.3.4
- =<2.25.16
- =<1.6.3
- =<2.6.5
- =<2.3.11
- =<3.0.2
- =<7.3.3
- =<2.6.0
- =<2.1
- =<1.1.5
- =<1.10.4
- =<3.12.1
- =<1.5.8
- =<5.222
- =<2.3.7
- =<2.7.33
- =<3.2.6
- =<2.24.6
- =<2.2.0
- =<3.0.6
- =<3.1.28
- =<3.12.0
- =<3.4.12
- =<5.17.2
- =<1.2.7
- =<2.8.6
- =<1.7.0
- =<1.4.9
- =<1.8.99
- =<3.3.2
- =<1.1.3
- =<2.4.1
- =<3.3.7
- =<1.9.8
- =<2.16.3.3
- =<1.7.0
- =<3.2.2
- =<2.5.9
- =<1.16.3
- =<2.4.1
- =<4.5.0
- =<1.5.10
- =<3.2.7
- =<6.1.13
- =<1.7.2
- =<2.0.82
- =<6.6.5
- =<2.1.0
- =<5.0.57
- =<2.2.27
- =<2.5.7
- =<4.6.8
- =<3.2.6
- =<5.5.31
- =<1.2.7
- =<2.1.34
- =<1.3.3
- =<2.5.9
- =<3.8.3
- =<3.2.8
- =<2.6.7
- =<2.3.0
- =<1.1.13
- =<8.0.7
- =<1.6.3
- =<3.4.9
- =<1.10.6
- =<2.9.2
- =<7.7.0
- =<3.2.7
- =<2.0.7.2
- =<2.5.8
- =<3.0.0
Matching in nixpkgs
pkgs.pyglossary
Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device
pkgs.mqttmultimeter
MQTT traffic monitor
pkgs.pyglossary-gui
Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device
pkgs.python312Packages.pyglossary
None
pkgs.python313Packages.pyglossary
Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device
pkgs.python314Packages.pyglossary
Tool for converting dictionary files aka glossaries. Mainly to help use our offline glossaries in any Open Source dictionary we like on any operating system / device
Package maintainers
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@doronbehar Doron Behar <me@doronbehar.com>