What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0.
Explanation of Vulnerability in Simple Terms
The Sticky banner plugin through version 1.2.0 contains a stored cross-site scripting (XSS) vulnerability. An authenticated user with high privileges can inject malicious JavaScript into the banner configuration. When other users view pages with the banner, the injected script executes in their browsers, potentially stealing session data or performing actions on their behalf.
What an attacker can do
Inject and execute malicious JavaScript in the browsers of site visitors.
Potential impact on your site
Visitors' browsers can be compromised if a privileged account is misused or compromised.
Conditions required to exploit
Attacker must have high-level admin or configuration access to the plugin settings.
Key dates
External resources
Related vulnerabilities