Bowo Vulnerabilities and Affected Products
Vulnerabilities associated with system_dashboard.
Products
Clear product- Debug Log Manager5 vulnerabilities
- Admin and Site Enhancements (ASE)4 vulnerabilities
- system_dashboard3 vulnerabilities
- Variable Inspector2 vulnerabilities
- System Dashboard1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-11107MEDIUM | System Dashboard < 2.8.15 - Unauthenticated Stored XSSThe System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks. CWE-79Dec 10, 2024 | CVSS6.1v3.1 | EPSS0.333% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10708MEDIUM | System Dashboard < 2.8.15 - Admin+ Path TraversalThe System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server | CVSS4.9v3.1 | EPSS2.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-7246MEDIUM | System Dashboard < 2.8.10 - XSS via Header InjectionThe System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks | CVSS5.4v3.1 | EPSS0.813% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |