What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
Explanation of Vulnerability in Simple Terms
Archivist – Custom Archive Templates versions up to 1.7.4 contain a cross-site scripting (XSS) vulnerability in template handling. An authenticated administrator can inject malicious scripts into archive templates. When another user views the affected template, the script executes in their browser, potentially compromising their session or stealing data. The vulnerability requires administrative access and user interaction to exploit.
What an attacker can do
Inject malicious scripts into archive templates that execute when other users view them.
Potential impact on your site
Administrators can be tricked into viewing malicious templates, risking session hijacking or data theft.
Conditions required to exploit
Administrator account access and the victim must view the affected template.
Key dates
External resources
Related vulnerabilities