Vulnerabilities > CVE-2022-1005 - Unspecified vulnerability in Veronalabs WP Statistics

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
veronalabs

Summary

The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

Vulnerable Configurations

Part Description Count
Application
Veronalabs
180