What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.10.13 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.10.13 versions.
Explanation of Vulnerability in Simple Terms
Daily Prayer Time contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. When another user views the affected content, the script executes in their browser with the same permissions as that user. The vulnerability requires user interaction to trigger and can affect other users on the site.
What an attacker can do
Inject malicious scripts that execute when other users view the affected content.
Potential impact on your site
Authenticated users can compromise other users' sessions, steal data, or perform actions on their behalf.
Conditions required to exploit
Attacker must be authenticated with low-level privileges; victim must view the page containing the injected script.
Key dates
External resources
Related vulnerabilities