Description Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280. Remediation References CVE-2018-14481 Related Vulnerabilities WordPress Plugin PublishPress Capabilities-User Role Access, Editor Permissions, Admin Menus Cross-Site Request Forgery (2.3.1) WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Unspecified Vulnerability (5.7) PHP Improper Certificate Validation Vulnerability (CVE-2015-3152) Envoy Proxy Reachable Assertion Vulnerability (CVE-2022-29228) MySQL CVE-2021-35624 Vulnerability (CVE-2021-35624) Severity Medium Classification CVE-2018-14481 CWE-707 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Tags Missing Update Known Vulnerabilities