CVE-2021-34630 Information
Jun 07, 2022
cve
Description
In the Pro and Enterprise versions of GTranslate < 2.8.65 the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER[‘REQUEST_URI’]. Although this uses addslashes and most modern browsers automatically URLencode requests this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below or in cases where an attacker is able to modify the request en route between the client and the server or in cases where the user is using an atypical browsing solution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://plugins.svn.wordpress.org/gtranslate/tags/2.8.64/gtranslate.php
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: