What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nuajik plugin <= 0.1.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nuajik plugin <= 0.1.0 versions.
Explanation of Vulnerability in Simple Terms
Nuajik versions up to 0.1.0 contain a cross-site scripting (XSS) vulnerability that allows an authenticated high-privilege user to inject malicious scripts. The vulnerability requires user interaction and affects the integrity and confidentiality of the application. Site administrators should update to a version newer than 0.1.0 when available.
What an attacker can do
Inject malicious scripts that execute in users' browsers when they visit affected pages.
Potential impact on your site
Authenticated high-privilege users can inject scripts affecting site visitors' data and trust.
Conditions required to exploit
Attacker must have high-level privileges and trick a user into visiting a malicious link or page.
Key dates
External resources
Related vulnerabilities