WordPress Plugin Vulnerabilities
Support Board < 1.2.4 - Stored Cross-Site Scripting
Description
The plugin does not sanitise and escape the msg parameter of the sb_ajax_add_message AJAX action, which could lead to Stored Cross-Site Scripting issues
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ismail Tasdelen
Verified
No
WPVDB ID
Timeline
Publicly Published
2018-10-16 (about 7 years ago)
Added
2019-08-24 (about 6 years ago)
Last Updated
2022-02-15 (about 4 years ago)