HomeDefault status
unaffected
Any version
affected
Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through <= 5.0.3.
Problem types
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Product status
Any version
Credits
Najib Sinjari | Patchstack Bug Bounty Program
References
vdp.patchstack.com/...tent-injection-vulnerability?_s_id=cve