What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions.
Explanation of Vulnerability in Simple Terms
OPcache Dashboard versions up to 0.3.1 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the dashboard interface. An attacker can craft a malicious link that, when clicked by a site administrator, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the admin.
What an attacker can do
Inject and execute malicious JavaScript in an admin's browser session via a crafted link.
Potential impact on your site
An admin visiting a malicious link could have their session compromised or credentials stolen.
Conditions required to exploit
Attacker must trick an admin into clicking a malicious link; no prior authentication required.
Key dates
External resources
Related vulnerabilities