Output Encoding Flaw in Poll Maker by Poll Maker Team
CVE-2024-56277

5.3MEDIUM

Key Information:

Vendor
Poll Maker Team
Status
Poll Maker
Vendor
CVE Published:
21 January 2025

Summary

An improper encoding or escaping of output vulnerability exists in Poll Maker by Poll Maker Team, which allows attackers to inject malicious HTML code. This flaw could lead to various security risks, enabling unauthorized users to manipulate or disrupt the integrity of web applications reliant on this plugin. It is crucial for users of Poll Maker to take immediate action to mitigate any potential impacts and ensure their web security remains robust.

Affected Version(s)

Poll Maker < 5.5.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Zidan Ali Mansur (Patchstack Alliance)
.