Persistent XSS Vulnerability in CityBook, TownHub, and EasyBook WordPress Themes
CVE-2019-20211
6.1MEDIUM
Summary
The CTHthemes CityBook, TownHub, and EasyBook WordPress themes are susceptible to a Persistent XSS vulnerability. This flaw allows attackers to inject malicious scripts through various fields, including Listing Address, Latitude, Longitude, Email Address, as well as other descriptive fields. If exploited, this vulnerability can lead to unauthorized access and data breaches, posing substantial risks to website users and the integrity of the applications.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved