What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.
Explanation of Vulnerability in Simple Terms
Slider Revolution versions up to 6.7.13 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious JavaScript that executes in the browsers of other users viewing the site. The vulnerability requires user interaction and affects the integrity and confidentiality of site data.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view the site.
Potential impact on your site
A compromised admin account can inject scripts affecting all site visitors, potentially stealing data or redirecting users.
Conditions required to exploit
Attacker must have high-level administrator privileges and the victim must visit an affected page.
Key dates
External resources
Related vulnerabilities