nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18590 CVE-2017-18590
MEDIUMNuclei
Timesheet Plugin < 0.1.5 - Cross-Site Scripting
Record summary
CVE-2017-18590 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMTimesheet Plugin < 0.1.5 - Cross-Site ScriptingCVSS 6.1
The Timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
Impact
Authenticated attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
Remediation
Update to version 0.1.5 or later.
WeaknessesCWE-79
AuthorsSplint3r7
Template tagscvecve2017wordpresswpwp-pluginbws-promobarxssauthenticatedtimesheetvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:bestwebsoft:promobar:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/efd816c3-90d4-40bf-850a-0e4c1a756694/ https://nvd.nist.gov/vuln/detail/CVE-2017-18590 https://downloads.wordpress.org/plugin/timesheet
Source: ProjectDiscovery
References
2wordpress.org
https://wordpress.org/plugins/timesheet