CVE-2014-125097: BestWebSoft Facebook Like Button facebook-button-plugin.php fcbkbttn_settings_page cross site scripting
A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttnsettingspage of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.34 is able to address this issue. The patch is identified as b766da8fa100779409a953f0e46c2a2448cbe99c. It is recommended to upgrade the affected component. VDB-225354 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2014-125097.
What is the severity rating of CVE-2014-125097?
The severity rating of CVE-2014-125097 is medium with a value of 6.1.
What is the affected software and version for CVE-2014-125097?
The affected software for CVE-2014-125097 is BestWebSoft Facebook Like Button up to version 2.33.
What is the CWE category for CVE-2014-125097?
The CWE category for CVE-2014-125097 is CWE-79 (Cross-Site Scripting).
Is it possible to launch the attack remotely for CVE-2014-125097?
Yes, it is possible to launch the attack remotely for CVE-2014-125097.