CVE-2015-5485
18.08.2015, 15:59
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.
Vendor | Product | Version |
---|---|---|
theeventscalendar | eventbrite_tickets | 𝑥 ≤ 3.10.1 |
𝑥
= Vulnerable software versions
References