What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions.
Explanation of Vulnerability in Simple Terms
Modal Dialog versions up to 3.5.14 contain a cross-site scripting vulnerability in how they handle user input within dialog content. An attacker can inject malicious scripts that execute in a visitor's browser when they interact with a modal dialog. The vulnerability requires user interaction—the visitor must click or interact with the affected modal—and can affect other parts of the page or session.
What an attacker can do
Inject and execute malicious JavaScript in a visitor's browser when they interact with a modal dialog.
Potential impact on your site
Visitors' sessions, cookies, or form data could be compromised if they interact with a malicious modal dialog.
Conditions required to exploit
Visitor must click or interact with a modal dialog containing the attacker's injected payload.
Key dates
External resources
Related vulnerabilities