CiviCRM < 5.28.1 - Cross-Site Request Forgery to Cross-Site Scripting
mediumThe CiviCRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper CSRF checks in the CKEditor Configuration Form in versions up to, and including, 5.28.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...
- CVSS:
- 6.1
- Affected:
- up to 5.28.0
- Fixed in:
- 5.28.1
- Disclosed:
- Jun 22, 2021