CVE-2024-6019Cross-site Scripting in Music Request Manager

Severity
6.1MEDIUMNVD
EPSS
1.1%
top 21.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12

Description

The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
Music Request Manager <= 1.3 - Unauthenticated Stored XSS2024-09-12
GHSA
GHSA-6x3x-mhgp-4j2c: The Music Request Manager WordPress plugin through 12024-09-12

💥Exploits & PoCs

1
Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)2024-04-12
CVE-2024-6019 — Cross-site Scripting | cvebase