RSS   Vulnerabilities for 'Admin menu'   RSS

2020-08-26
 
CVE-2020-24316

CWE-79
 

 
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

 


Copyright 2020, cxsecurity.com

 

Back to Top