What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AB-WP Simple Counter allows Stored XSS.This issue affects Simple Counter: from n/a through 1.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AB-WP Simple Counter allows Stored XSS.This issue affects Simple Counter: from n/a through 1.0.2.
Explanation of Vulnerability in Simple Terms
Simple Counter versions up to 1.0.2 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts that execute in the browsers of other site users. The vulnerability requires an admin to craft a malicious input and a user to view the affected page. This can lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view the counter.
Potential impact on your site
Admins can unknowingly inject malware affecting all site visitors; user accounts and data at risk.
Conditions required to exploit
Attacker must have administrator privileges and the victim must visit a page displaying the counter.
Key dates
External resources
Related vulnerabilities