What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions.
Explanation of Vulnerability in Simple Terms
Archivist – Custom Archive Templates versions up to 1.7.5 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted page. The vulnerability requires user interaction and affects the integrity and confidentiality of site data. Update to a version newer than 1.7.5.
What an attacker can do
Inject malicious scripts that run in a visitor's browser and steal data or perform actions on their behalf.
Potential impact on your site
Visitors' browsers can be compromised; their session tokens, passwords, or personal data may be stolen.
Conditions required to exploit
Victim must visit a page containing the attacker's malicious input; no authentication required.
Key dates
External resources
Related vulnerabilities