First published: Thu Mar 23 2023(Updated: )
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mage-people Event Manager And Tickets Selling Plugin For Woocommerce | <3.8.7 |
Update to 3.8.7 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28422 is medium with a severity value of 4.8.
CVE-2023-28422 is an authentication (admin+) stored cross-site scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6 versions.
The affected software is MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6 versions.
To fix CVE-2023-28422, update MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce to version 3.8.7 or higher.
The Common Weakness Enumeration (CWE) of CVE-2023-28422 is CWE-79 (Cross-site Scripting).