CVE-2023-0253

Rejected reason: **REJECT** Accidental CVE Assignment. Please use CVE-2023-0285.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

06 Aug 2024, 14:16

Type Values Removed Values Added
Summary (en) The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via folder names in versions up to, and including, 4.18.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. (en) Rejected reason: **REJECT** Accidental CVE Assignment. Please use CVE-2023-0285.
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : unknown
CPE cpe:2.3:a:devowl:wordpress_real_media_library:*:*:*:*:*:wordpress:*:*
References
  • {'url': 'https://devowlio.gitbook.io/changelogs/wordpress-plugins/real-media-library', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': 'security@wordfence.com'}
  • {'url': 'https://wordpress.org/plugins/real-media-library-lite/', 'tags': ['Product', 'Third Party Advisory'], 'source': 'security@wordfence.com'}
  • {'url': 'https://www.wordfence.com/threat-intel/vulnerabilities/id/950d71ae-29a1-4b71-b74a-b1a5c9f3326e', 'tags': ['Third Party Advisory'], 'source': 'security@wordfence.com'}

03 Feb 2023, 14:01

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-02 21:22

Updated : 2024-08-06 14:16


NVD link : CVE-2023-0253

Mitre link : CVE-2023-0253

CVE.ORG link : CVE-2023-0253


JSON object : View

Products Affected

No product.

CWE

No CWE.