cleantalk
Vulnerabilities and Security Researches

Clean Login, bb61c8c631c4e3f230fa416217fad1faed0bc7cc

Application

Clean Login

Published on
Aug 09, 2021
Research Description
Clean Login [clean-login] < 1.12.6.4 Clean Login 1.12.6.3 - Cross-Site Scripting The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.12.6.4.
Status
vulnerable