CVE-2023-4294

CVE-2023-4294

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

Source: CVE-2023-4294

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다