Vulnerability Name: | CVE-2011-5182 | ||||||||
Assigned: | 2012-09-20 | ||||||||
Published: | 2012-09-20 | ||||||||
Updated: | 2018-10-09 | ||||||||
Summary: | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. Note: the vendor disputes this issue, stating "Lanoba's plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user's behalf." | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-5182 Source: BUGTRAQ Type: UNKNOWN 20111119 wordpress Lanoba Social Plugin Xss Vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20111129 Re: Re: wordpress Lanoba Social Plugin Xss Vulnerabilities Source: BID Type: Exploit 50746 Source: XF Type: UNKNOWN lanobasocial-index-xss(71411) Source: MISC Type: Vendor Advisory https://wordpress.org/support/topic/plugin-lanoba-social-plugin-xss-vulnerabilities | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |