CVE-2018-20368Cross-site Scripting in Master Slider

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 49.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateMay 14

Description

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDaverta/master_slider3.2.7, 3.5.1+1

🔴Vulnerability Details

1
GHSA
GHSA-3866-cc7f-3jx4: The Master Slider plugin 32022-05-14