Tera Charts <= 1.0 - Reflected Cross-Site Scripting
mediumReflected XSS in wordpress plugin tera-charts v1.0 via fn parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 17, 2016
plugin
4 known security issues reported for the Tera Charts WordPress plugin. Most recent disclosed Oct 17, 2016.
Running Tera Charts on your site? Check whether your installed version is affected.
Scan your site freeReflected XSS in wordpress plugin tera-charts v1.0 via fn parameter.
[en] Reflected XSS in wordpress plugin tera-charts v1.0
[en] Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free