What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50.
Explanation of Vulnerability in Simple Terms
WPMobile.App versions 11.50 and earlier contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker can craft a malicious link or page that, when visited by a user, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
Inject and execute malicious JavaScript in a user's browser to steal data or hijack sessions.
Potential impact on your site
Users visiting affected pages can have their sessions compromised or credentials stolen; site reputation may be damaged.
Conditions required to exploit
User must visit a malicious link or page crafted by the attacker; no authentication required.
Key dates
External resources
Related vulnerabilities