CVE-2022-25276

CVE-2022-25276

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.

Source: CVE-2022-25276

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다