Vulnerabilities > CVE-2023-4950 - Unspecified vulnerability in Funnelforms
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |