CVE-2020-24316
EUVD-2020-1705026.08.2020, 14:15
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| admin_menu_project | admin_menu | 𝑥 ≤ 1.1 |
𝑥
= Vulnerable software versions