{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-3288","assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","state":"PUBLISHED","assignerShortName":"WPScan","dateReserved":"2024-04-03T20:31:04.876Z","datePublished":"2024-06-07T06:00:02.259Z","dateUpdated":"2024-11-06T23:14:21.788Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan","dateUpdated":"2024-06-07T06:00:02.259Z"},"title":"Logo Slider < 4.0.0 - Contributor+ Stored XSS","problemTypes":[{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"affected":[{"vendor":"Unknown","product":"Logo Slider ","versions":[{"status":"affected","versionType":"semver","version":"0","lessThan":"4.0.0"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Logo Slider  WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks"}],"references":[{"url":"https://wpscan.com/vulnerability/4ef99f54-68df-4353-8fc0-9b09ac0df7ba/","tags":["exploit","vdb-entry","technical-description"]}],"credits":[{"lang":"en","value":"Krugov Artyom","type":"finder"},{"lang":"en","value":"WPScan","type":"coordinator"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"WPScan CVE Generator"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"CHANGED","version":"3.1","baseScore":5.4,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","integrityImpact":"LOW","userInteraction":"REQUIRED","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-06-07T10:01:10.360342Z","id":"CVE-2024-3288","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-06T23:14:21.788Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T20:05:08.225Z"},"title":"CVE Program Container","references":[{"url":"https://wpscan.com/vulnerability/4ef99f54-68df-4353-8fc0-9b09ac0df7ba/","tags":["exploit","vdb-entry","technical-description","x_transferred"]}]}]}}