What the vulnerability does
01Description
Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformatie plugin <= 2.0.14 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformatie plugin <= 2.0.14 versions.
Explanation of Vulnerability in Simple Terms
The Open RDW kenteken voertuiginformatie product through version 2.0.14 contains a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted link. The vulnerability requires user interaction and can affect confidentiality, integrity, and availability of the affected site.
What an attacker can do
Inject malicious scripts that run in a victim's browser to steal data, modify page content, or perform actions on their behalf.
Potential impact on your site
Visitors to your site can be redirected, have their session hijacked, or see modified content if they click a malicious link.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page that triggers the vulnerability.
Key dates
External resources
Related vulnerabilities