CVE-2015-9370: XSS
Published Aug 28, 2019
·Updated
Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via addqueryarg() and removequeryarg().
Affected Software
1 affected component
iThemes Invoices Wordpress<1.4.0
Event History
Aug 28, 2019
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Invoices Add-on for iThemes Exchange?
The vulnerability ID for the Invoices Add-on for iThemes Exchange is CVE-2015-9370.
2
What is the severity of CVE-2015-9370?
The severity of CVE-2015-9370 is medium.
3
What software is affected by CVE-2015-9370?
The Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress is affected by CVE-2015-9370.
4
How does CVE-2015-9370 exploit the vulnerability?
CVE-2015-9370 exploits the vulnerability through the use of add_query_arg() and remove_query_arg() functions in the Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress, allowing for cross-site scripting (XSS) attacks.
5
Are there any references for CVE-2015-9370?
Yes, you can find references for CVE-2015-9370 at the following links: [link1] [link2].