What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.
Explanation of Vulnerability in Simple Terms
JSON Content Importer versions up to 1.3.15 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts through the importer interface. When other users view affected content, the scripts execute in their browsers, potentially compromising their sessions or stealing data. The vulnerability requires user interaction and affects the scope beyond the vulnerable component.
What an attacker can do
Inject malicious scripts that execute when other users view imported content.
Potential impact on your site
Administrators can inadvertently inject malicious code affecting all site visitors who view imported content.
Conditions required to exploit
Attacker must have high-level administrator privileges and a victim must view the affected content.
Key dates
External resources
Related vulnerabilities