CVE-2008-1304: XSS
Published Mar 12, 2008
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
Affected Software
1 affected component
WordPress=2.3.2
Event History
Mar 12, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1304?
CVE-2008-1304 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-1304?
To fix CVE-2008-1304, upgrade to a later version of WordPress that addresses the XSS vulnerabilities.
3
What versions of WordPress are affected by CVE-2008-1304?
CVE-2008-1304 specifically affects WordPress version 2.3.2.
4
What type of vulnerability is CVE-2008-1304?
CVE-2008-1304 is classified as a multiple cross-site scripting (XSS) vulnerability.
5
Can CVE-2008-1304 be exploited remotely?
Yes, CVE-2008-1304 can be exploited remotely by attackers looking to inject malicious scripts.