cleantalk
Vulnerabilities and Security Researches

SlimStat Analytics, CVE-2015-1204

CVE, Research URL

CVE-2015-1204

Application

SlimStat Analytics

Published on
Jan 21, 2015
Research Description
Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php.
Affected versions
max 3.9.3.
Status
vulnerable