The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
2022-03-07T09:15:08.363
2024-11-21T05:54:04.477
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Application | tinywebgallery | advanced_iframe | < 2022 | Yes |