First published: Thu Nov 16 2023(Updated: )
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Marcomilesi Anac Xml Bandi Di Gara | <=7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-47242 is medium with a severity value of 6.5.
The vulnerability in WordPress ANAC XML Bandi di Gara Plugin <= 7.5 is a Stored Cross-Site Scripting (XSS) vulnerability.
The vulnerability in WordPress ANAC XML Bandi di Gara Plugin <= 7.5 affects the software by allowing an attacker with contributor+ authentication to store malicious scripts that are executed in a user's browser.
The vulnerability in WordPress ANAC XML Bandi di Gara Plugin <= 7.5 can be exploited by an attacker with contributor+ authentication who submits malicious scripts that are stored and later executed in a user's browser.
To fix the vulnerability in WordPress ANAC XML Bandi di Gara Plugin <= 7.5, you should update to a version higher than 7.5 that addresses the Cross-Site Scripting (XSS) vulnerability.