The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:25:40.210Z
Reserved: 2022-01-26T00:00:00
Link: CVE-2022-0385

No data.

Status : Modified
Published: 2022-02-28T09:15:09.197
Modified: 2024-11-21T06:38:30.750
Link: CVE-2022-0385

No data.