CVE-2019-17550: XSS
Published Nov 13, 2019
·Updated
The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2sid parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
Affected Software
1 affected component
Adenion Blog2social Wordpress<5.9.0
Remediation
Patch Available
Event History
Nov 13, 2019
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Blog2Social plugin in WordPress?
The vulnerability ID for the Blog2Social plugin in WordPress is CVE-2019-17550.
2
What is the severity of CVE-2019-17550?
The severity of CVE-2019-17550 is medium.
3
How does CVE-2019-17550 in the Blog2Social plugin impact the system?
CVE-2019-17550 allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter.
4
Which component of the Blog2Social plugin is affected by CVE-2019-17550?
The component affected by CVE-2019-17550 is views/b2s/post.calendar.php.
5
How can I fix CVE-2019-17550 in the Blog2Social plugin?
To fix CVE-2019-17550, update the Blog2Social plugin to version 5.9.0 or above.