What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in All My Web Needs Logo Scheduler plugin <= 1.2.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in All My Web Needs Logo Scheduler plugin <= 1.2.0 versions.
Explanation of Vulnerability in Simple Terms
Logo Scheduler through version 1.2.0 contains a cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious scripts. An attacker with high-level privileges can craft a malicious link or page that, when visited by a site administrator, executes arbitrary JavaScript in the admin's browser. This can lead to unauthorized actions or data theft within the site.
What an attacker can do
Run malicious JavaScript in an administrator's browser to steal credentials or perform unauthorized site actions.
Potential impact on your site
Administrators visiting malicious links could have their sessions compromised or site settings altered without their knowledge.
Conditions required to exploit
Attacker must have high-level site privileges and trick an admin into visiting a crafted link or page.
Key dates
External resources
Related vulnerabilities