CVE-2020-24314
Summary
| CVE | CVE-2020-24314 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-26 13:15:00 UTC |
| Updated | 2020-09-03 19:03:00 UTC |
| Description | Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rss Feed Widget Project | Rss Feed Widget | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RSS Feed Widget (advanced view) – WordPress plugin | WordPress.org | MISC | wordpress.org | Product, Third Party Advisory |
| WordPress Plugin Bug Hunting - Part 1 - Zero Aptitude | MISC | zeroaptitude.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.