Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS.
This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Fontsplugin Disable_And_Remove_Google_Fonts_Gdpr_Dsgvo_Friendly
cpe:2.3:a:fontsplugin:disable_and_remove_google_fonts_gdpr_dsgvo_friendly:*:*:*:*:*:*:*:*
|
n_a
|
<= 2.0.2
|