CVE-2024-6020
04.09.2024, 06:15
The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.
Vendor | Product | Version |
---|---|---|
fetchdesigns | sign-up_sheets | 𝑥 < 2.2.13 |
𝑥
= Vulnerable software versions