MEDIUM
Real Media Library < 4.18.29 - Author+ Stored XSS
Published Feb 21, 2023
5.4
MEDIUMCVSS 3.1
EPSS 0.46%
Description
The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
Affected products
- Vendor n/a Product Real Media Library: Media Library Folder & File Manager Defaultunaffected
Affected
- ≥ 0, < 4.18.29
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Real Media Library: Media Library Folder & File Manager | unaffected | Affected
|
- < 4.18.29
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12364 Advisory
- https://wpscan.com/vulnerability/adf09e29-baf5-4426-a281-6763c107d348 exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12364 | Advisory | |
| https://wpscan.com/vulnerability/adf09e29-baf5-4426-a281-6763c107d348 | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Feb 21, 2023
Updated Mar 12, 2025
Reserved Jan 13, 2023
Link CVE-2023-0285
CISA Vulnrichment
Updated Mar 12, 2025
Red Hat
No data
GitHub
No data