cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forclio-grow-form clio-grow-form

Direction: ascending
Jun 07, 2024

Clio Grow # CVE-2023-22683

CVE, Research URL

CVE-2023-22683

Application

Clio Grow

Date
May 03, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themis Solutions, Inc. Clio Grow plugin <= 1.0.0 versions.
Affected versions
max 1.0.1.
Status
vulnerable
Oct 05, 2024

Clio Grow # CVE-2024-8802

CVE, Research URL

CVE-2024-8802

Application

Clio Grow

Date
Oct 04, 2024
Research Description
The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.0.3.
Status
vulnerable
Oct 19, 2024

Clio Grow # CVE-2024-49276

CVE, Research URL

CVE-2024-49276

Application

Clio Grow

Date
Oct 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themis Solutions, Inc. Clio Grow allows Reflected XSS.This issue affects Clio Grow: from n/a through 1.0.2.
Affected versions
max 1.0.3.
Status
vulnerable