WordPress Plugin Vulnerabilities

Support Board < 1.2.4 - Stored Cross-Site Scripting

Description

The plugin does not sanitise and escape the msg parameter of the sb_ajax_add_message AJAX action, which could lead to Stored Cross-Site Scripting issues

Affects Plugins

Fixed in 1.2.4

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ismail Tasdelen
Verified
No

Timeline

Publicly Published
2018-10-16 (about 7 years ago)
Added
2019-08-24 (about 6 years ago)
Last Updated
2022-02-15 (about 4 years ago)

Other