WordPress 插件“Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More”存在反射型基于 DOM 的跨站脚本漏洞(Reflected DOM-Based Cross-Site Scripting),该漏洞影响所有 5.5.1.5 及之前版本。漏洞原因是输入净化不足以及输出转义不充分,攻击者可通过 参数进行攻击。 此漏洞使得未认证的攻击者能够向网页中注入任意 Web 脚本,当用户
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| codepeople | Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More | ≤ 5.5.1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| codepeople | Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More | 0 ~ 5.5.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet