CVE-2022-0901
04.04.2022, 16:15
The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
Vendor | Product | Version |
---|---|---|
ad_inserter_project | ad_inserter | 𝑥 < 2.7.12 |
ad_inserter_project | ad_inserter | 𝑥 < 2.7.12 |
𝑥
= Vulnerable software versions
References