PT-2025-43024 · Rpetersen29+1 · Simple Banner – Easily Add Multiple Banners/Bars/Notifications/Announcements To The Top/Bottom Of Your Website+1
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Banner versions prior to 3.0.11
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with administrator-level access can inject arbitrary web scripts via the
pro version activation code parameter. These scripts execute when a user accesses an affected page. This issue specifically impacts multi-site installations and environments where unfiltered html has been disabled.Recommendations
Update to version 3.0.11 or later.
Avoid using the
pro version activation code parameter until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Banner – Easily Add Multiple Banners/Bars/Notifications/Announcements To The Top/Bottom Of Your Website
Simple Banner