CVE-2023-3186

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:supsystic:popup:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 04:18

Type Values Removed Values Added
CWE CWE-1321

28 Jul 2023, 13:24

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/545007fc-3173-47b1-82c4-ed3fd1247b9c - (MISC) https://wpscan.com/vulnerability/545007fc-3173-47b1-82c4-ed3fd1247b9c - Exploit, Third Party Advisory
CPE cpe:2.3:a:supsystic:popup:*:*:*:*:*:wordpress:*:*
First Time Supsystic
Supsystic popup
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

17 Jul 2023, 14:22

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-17 14:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-3186

Mitre link : CVE-2023-3186

CVE.ORG link : CVE-2023-3186


JSON object : View

Products Affected

supsystic

  • popup
CWE

No CWE.