What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versions.
Explanation of Vulnerability in Simple Terms
SpamReferrerBlock through version 2.22 contains a cross-site scripting (XSS) vulnerability that allows an authenticated administrator to inject malicious scripts. The vulnerability requires user interaction—typically clicking a crafted link—and affects the integrity and confidentiality of site data. An attacker with high-level privileges can execute JavaScript in the context of other users' browsers.
What an attacker can do
Inject and execute malicious JavaScript in the admin panel or site frontend, affecting other users' sessions.
Potential impact on your site
An admin account could be compromised or manipulated to perform unintended actions; site data and user sessions at risk.
Conditions required to exploit
Attacker must have administrator-level access and trick a user into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities