What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcel Bootsman Auto Hide Admin Bar plugin <= 1.6.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcel Bootsman Auto Hide Admin Bar plugin <= 1.6.1 versions.
Explanation of Vulnerability in Simple Terms
Auto Hide Admin Bar versions up to 1.6.1 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious JavaScript that executes in the browsers of other site users. The vulnerability requires an admin to craft a malicious input and a user to interact with the affected page. This can lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
Inject JavaScript that runs in other users' browsers when they view the admin bar.
Potential impact on your site
A compromised admin account can inject malicious code affecting all site visitors, potentially stealing credentials or spreading malware.
Conditions required to exploit
Attacker must have administrator privileges and the victim must visit a page containing the injected payload.
Key dates
External resources
Related vulnerabilities