Vulnerabilities and security researches forclio-grow-form clio-grow-form
Direction: ascendingJun 07, 2024
Clio Grow # CVE-2023-22683
- CVE, Research URL
- Home page URL
- Application
- Date
- May 03, 2023
- Research Description
- Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themis Solutions, Inc. Clio Grow plugin <= 1.0.0 versions.
- Affected versions
-
max 1.0.1.
- Status
-
vulnerable
Oct 05, 2024
Clio Grow # CVE-2024-8802
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 04, 2024
- Research Description
- The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.0.3.
- Status
-
vulnerable
Oct 19, 2024
Clio Grow # CVE-2024-49276
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 18, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themis Solutions, Inc. Clio Grow allows Reflected XSS.This issue affects Clio Grow: from n/a through 1.0.2.
- Affected versions
-
max 1.0.3.
- Status
-
vulnerable