What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in hupe13 Extensions for Leaflet Map plugin <= 3.4.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in hupe13 Extensions for Leaflet Map plugin <= 3.4.1 versions.
Explanation of Vulnerability in Simple Terms
Extensions for Leaflet Map versions up to 3.4.1 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts. An attacker can craft a malicious link or page that, when visited by a site user, executes arbitrary JavaScript in the user's browser. This can lead to session hijacking, credential theft, or defacement.
What an attacker can do
Inject and execute malicious JavaScript in a user's browser when they visit a crafted page or link.
Potential impact on your site
Site visitors' sessions, credentials, or data can be compromised if they interact with attacker-controlled content.
Conditions required to exploit
A site user must visit a page or click a link controlled or crafted by the attacker.
Key dates
External resources
Related vulnerabilities