PT-2023-10173 · WordPress · Broken Link Checker Plugin
CVE-2014-125105
·
Publicado
2023-06-05
·
Atualizado
2024-05-17
CVSS v2.0
3.3
Baixa
| Vetor | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Broken Link Checker Plugin versions up to 1.10.1
Description
A vulnerability was found in the Broken Link Checker Plugin. It affects the function
options page of the file core/core.php of the component Settings Page. The manipulation of the argument exclusion list/blc custom fields leads to cross-site scripting. The attack can be launched remotely.Recommendations
For Broken Link Checker Plugin versions up to 1.10.1, upgrade to version 1.10.2 to address this issue. As a temporary workaround, consider restricting access to the
options page function of the Settings Page component until the upgrade is applied.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Broken Link Checker Plugin