Header Footer Code Manager < 1.1.24 - Cross-Site Scripting (CVE-2022-0899)
收藏pentest-tools.com2025-03-23 收录
下载链接:
https://pentest-tools.com/vulnerabilities-exploits/undefined
下载链接
链接失效反馈官方服务:
资源简介:
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.
WordPress插件“Header Footer Code Manager”在版本1.1.24之前,未能对生成的URL进行转义处理,在输出至管理页面的属性中时,导致反射型跨站脚本攻击。
提供机构:
pentest-tools.com



