The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/2656512 | Patch Third Party Advisory |
https://wpscan.com/vulnerability/f274b0d8-74bf-43de-9051-29ce36d78ad4 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Feb 2022, 04:21
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.1 |
CPE | cpe:2.3:a:permalink_manager_project:permalink_manager:*:*:*:*:pro:wordpress:*:* cpe:2.3:a:permalink_manager_lite_project:permalink_manager_lite:*:*:*:*:*:wordpress:*:* |
|
References | (MISC) https://wpscan.com/vulnerability/f274b0d8-74bf-43de-9051-29ce36d78ad4 - Exploit, Third Party Advisory | |
References | (CONFIRM) https://plugins.trac.wordpress.org/changeset/2656512 - Patch, Third Party Advisory |
14 Feb 2022, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-02-14 12:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-0201
Mitre link : CVE-2022-0201
CVE.ORG link : CVE-2022-0201
JSON object : View
Products Affected
permalink_manager_lite_project
- permalink_manager_lite
permalink_manager_project
- permalink_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')