CVE Published: 12/09/2024 |
CVE Updated: 12/09/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: Music Request Manager Status : PUBLISHED
CVE-2024-6018 Description
The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER[\'REQUEST_URI\'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers