漏洞标题
BestWebSoft联系表插件contact_form.php cntctfrm_check_form跨站脚本攻击
漏洞描述信息
BestWebSoft Contact Form Plugin的contact_form.php文件中的cntctfrm_check_form跨站脚本漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
BestWebSoft Contact Form Plugin contact_form.php cntctfrm_check_form cross site scripting
漏洞描述信息
A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 3.52 is able to address this issue. The patch is identified as 642ef1dc1751ab6642ce981fe126325bb574f898. It is recommended to upgrade the affected component. VDB-225002 is the identifier assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Wordpress Plugin BestWebSoft Contact Form 跨站脚本漏洞
漏洞描述信息
WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 Wordpress Plugin BestWebSoft Contact Form 存在跨站脚本漏洞。攻击者利用该漏洞可以执行跨站脚本攻击。
CVSS信息
N/A
漏洞类别
跨站脚本