Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-04T17:57:33.499Z
Reserved: 2023-08-09T02:20:30.651Z
Link: CVE-2023-40068
Updated: 2024-08-02T18:24:55.443Z
Status : Modified
Published: 2023-08-21T09:15:10.430
Modified: 2024-11-21T08:18:38.120
Link: CVE-2023-40068
No data.
OpenCVE Enrichment
No data.
Weaknesses