The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-02-21T08:50:42.950Z

Updated: 2023-02-21T08:50:42.950Z

Reserved: 2023-01-13T10:17:26.382Z


Link: CVE-2023-0285

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-02-21T09:15:12.257

Modified: 2023-11-07T04:00:05.790


Link: CVE-2023-0285

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.