What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Koch Mendeley Plugin plugin <= 1.3.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Koch Mendeley Plugin plugin <= 1.3.2 versions.
Explanation of Vulnerability in Simple Terms
The Mendeley Plugin through version 1.3.2 contains a cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious scripts. An attacker with high-level privileges can craft a request that, when a user visits a page, executes arbitrary JavaScript in their browser. The vulnerability affects the plugin's scope beyond its immediate component.
What an attacker can do
Inject and execute malicious JavaScript in users' browsers when they visit affected pages.
Potential impact on your site
An admin account compromise could allow script injection affecting other users' sessions and data.
Conditions required to exploit
Attacker must have administrator-level access and the victim must visit a page containing the malicious payload.
Key dates
External resources
Related vulnerabilities