Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-07-16T20:00:00

Updated: 2018-07-27T09:57:01

Reserved: 2018-07-10T00:00:00


Link: CVE-2018-13832

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-16T20:29:00.550

Modified: 2018-09-13T13:55:14.850


Link: CVE-2018-13832

JSON object: View

cve-icon Redhat Information

No data.

CWE