Cross-Site Scripting Vulnerability in SabaiApps WordPress Directories Pro
CVE-2020-29304
6.1MEDIUM
Summary
A cross-site scripting vulnerability exists within the SabaiApps WordPress Directories Pro plugin that affects version 1.3.45 and earlier. This issue arises when a site administrator is tricked into importing a specially crafted CSV file, which can lead to the execution of arbitrary web scripts or HTML. This situation poses a significant security concern, as it allows attackers to exploit the import workflow to inject malicious content, potentially compromising the security of the affected site and its users.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved