CVE-2023-1861 Vulnerability Details
/
/
/
CVE-2023-1861 Metadata Quick Info
CVE Published: 02/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023
Source: WPScan |
Vendor: Unknown |
Product: Limit Login Attempts
Status : PUBLISHED
CVE-2023-1861 Description
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: CWE-79 Cross-Site Scripting (XSS)
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).