Filtered by vendor Jsmol2wp Project
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-20463 | 1 Jsmol2wp Project | 1 Jsmol2wp | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF. | |||||
CVE-2018-20462 | 1 Jsmol2wp Project | 1 Jsmol2wp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter. |