Description
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Meta Data and Taxonomies Filter (MDTF) PHP Object Injection (1.2.2)
WordPress Plugin Import all XML, CSV & TXT into WordPress Server-Side Request Forgery (6.5.2)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5095)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-0541)