Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2351

Sept. 16, 2022, 9:15 a.m. |

National Vulnerability Database nist.gov

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.

cve

Cybersecurity Engineer

@ Apercen Partners LLC | Folsom, CA

IDM Sr. Security Developer

@ The Ohio State University | Columbus, OH, United States

IT Security Engineer

@ Stylitics | New York City

Information Security Engineer

@ VDA Labs | Remote

Information Security Analyst

@ Metropolitan Transportation Commission | San Francisco, CA

Personnel Security Specialist I

@ NT Concepts | Remote

Cyber Security Manager (SOC/Threat Detection)

@ Nubank | São Paulo

Personnel Security Specialist II

@ NT Concepts | Remote

Infrastructure Consultant - Graduate

@ Netcompany | Leeds, United Kingdom

Senior Cloud Network Security Engineer with expertise in WIFI technologies

@ Uni Systems | Luxembourg, Luxembourg, Luxembourg

DevSecOps Engineer - TOP SECRET Clearance Required - Colorado Springs/Denver/Pueblo

@ Spry Squared, Inc. | Colorado Springs, CO, United States

Product Security Associate

@ Mekari | Jakarta, Jakarta, Indonesia