CVE-2024-1273Cross-site Scripting in Starbox

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
Latest updateJun 19

Description

The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDsquirrly/starbox< 3.5.0

🔴Vulnerability Details

2
CVEList
Starbox < 3.5.0 - Contributor+ Stored XSS2024-03-11
GHSA
GHSA-jjxx-788m-fv7g: The Starbox WordPress plugin before 32024-03-11

📋Vendor Advisories

1
Red Hat
kernel: wifi: ath12k: fix out-of-bound access of qmi_invoke_handler()2024-06-19
CVE-2024-1273 — Cross-site Scripting in Starbox | cvebase