Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://nendeb.jp/fudou | third party advisory product |
https://www.nendeb-biz.jp/2021-0617-1200/ | third party advisory patch |
https://jvn.jp/en/jp/JVN93799513/index.html | third party advisory |