CVE-2022-25611
EUVD-2022-3027125.03.2022, 19:15
Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| presstigers | simple_event_planner | 𝑥 ≤ 1.5.4 |
𝑥
= Vulnerable software versions
References