The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/c5c30191-857c-419c-9096-d1fe14d34eaa/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-03-25 06:15
Updated : 2026-01-15 19:49
NVD link : CVE-2025-1798
Mitre link : CVE-2025-1798
CVE.ORG link : CVE-2025-1798
JSON object : View
Products Affected
italia
- design_comuni_italia
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
