vendor:
ThreeWP Email Reflector
by:
loneferret
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: ThreeWP Email Reflector
Affected Version From: 1.13
Affected Version To: 1.13
Patch Exists: YES
Related CWE: N/A
CPE: a:mindreantre:threewp_email_reflector
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu Server LAMP 8.04, MAC OS Lion
2012
ThreeWP Email Reflector XSS Vulnerability
ThreeWP Email Reflector is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can send a malicious email with a specially crafted payload to the victim. The payload is then executed in the victim's browser, allowing the attacker to gain access to the victim's session and other sensitive information.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the plugin.