CVE-2021-30134
MEDIUM
6,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0300
Percentile
0,9th
Updated
EPSS Score Trend (Last 90 Days)
79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Availability
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
AI/ML, Web Based, Web Server
Application
Php Curl Class by Php Curl Class Project
Version Range Affected
To
2.3.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:php_curl_class_project:php_curl_class:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Shopello Api by Shopello Api Project
Version Range Affected
To
2.9.0
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:shopello_api_project:shopello_api:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Invoicing With Invoicexpress For Woocommerce by Ptwooplugins
Version Range Affected
To
3.0.3
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:ptwooplugins:invoicing_with_invoicexpress_for_woocommerce:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Teamleader Crm Forms by Teamleade
Version Range Affected
To
2.1.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:teamleade:teamleader_crm_forms:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Woo-Qiwi-Payment-Gateway by Qiwi
Version Range Affected
To
0.0.9
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:qiwi:woo-qiwi-payment-gateway:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Ht Slider Range For Amazon Affiliates by Ht Slider Range For Amazon Affiliates Project
Version Range Affected
To
1.1.6
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:ht_slider_range_for_amazon_affiliates_project:ht_slider_range_for_amazon_affiliates:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://wpscan.com/vulnerability/0b547728-27d2-402e-ae17-90d539344ec7
https://wpscan.com/vulnerability/0b547728-27d2-402e-ae17-90d539344ec7