What the vulnerability does
01Description
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Explanation of Vulnerability in Simple Terms
MailOptin versions up to 1.2.78.0 contain a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level access can craft a request that executes JavaScript in other users' browsers, potentially compromising accounts or stealing data. The vulnerability requires user interaction and affects the scope beyond the vulnerable component.
What an attacker can do
Inject and execute JavaScript code in other users' browsers to steal data or compromise accounts.
Potential impact on your site
Authenticated users' sessions and data can be compromised if they interact with attacker-controlled content.
Conditions required to exploit
Attacker needs a low-privilege account and must trick a user into visiting a malicious link or page.
Key dates
External resources
Related vulnerabilities