Output Encoding Flaw in Poll Maker by Poll Maker Team
CVE-2024-56277
5.3MEDIUM
Key Information:
- Vendor
- Poll Maker Team
- Status
- Poll Maker
- Vendor
- CVE Published:
- 21 January 2025
Summary
An improper encoding or escaping of output vulnerability exists in Poll Maker by Poll Maker Team, which allows attackers to inject malicious HTML code. This flaw could lead to various security risks, enabling unauthorized users to manipulate or disrupt the integrity of web applications reliant on this plugin. It is crucial for users of Poll Maker to take immediate action to mitigate any potential impacts and ensure their web security remains robust.
Affected Version(s)
Poll Maker < 5.5.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Zidan Ali Mansur (Patchstack Alliance)