Vulnerabilities > CVE-2022-0953 - Unspecified vulnerability in Download Anti-Malware Security and Brute-Force Firewall Project Download Anti-Malware Security and Brute-Force Firewall
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |