What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.
Explanation of Vulnerability in Simple Terms
Tippy versions up to 6.2.1 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level account access can craft input that executes in other users' browsers when they view affected content. The vulnerability requires user interaction—the victim must visit a page containing the injected payload. Impact is limited to the Tippy component itself.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view affected content.
Potential impact on your site
Authenticated users can inject scripts affecting other users' sessions, potentially stealing credentials or performing actions on their behalf.
Conditions required to exploit
Attacker must have a low-privilege account on the site; victim must visit a page with the injected payload.
Key dates
External resources
Related vulnerabilities