vendor:
BP Group Documents
by:
Tom Adams
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: BP Group Documents
Affected Version From: 1.2.2001
Affected Version To: 1.2.2001
Patch Exists: YES
Related CWE:
CPE: a:wordpress:bp_group_documents:1.2.1
Platforms Tested:
2013
Stored XSS vulnerability in BP Group Documents
The 'Display name' and 'Description' fields in BP Group Documents 1.2.1 are not escaped, allowing for the storage of script tags and potential XSS attacks.
Mitigation:
Update to version 1.2.2.