CVE-2022-1757

The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues
Configurations

Configuration 1 (hide)

cpe:2.3:a:pagebar_project:pagebar:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:41

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/e648633e-868b-45b2-870a-308a2f9cb7f5 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/e648633e-868b-45b2-870a-308a2f9cb7f5 - Exploit, Third Party Advisory

08 Aug 2022, 14:15

Type Values Removed Values Added
CWE CWE-79
Summary The Pagebar WordPress plugin through 2.65 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues

15 Jul 2022, 19:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 5.4
CPE cpe:2.3:a:pagebar_project:pagebar:*:*:*:*:*:wordpress:*:*
References (MISC) https://wpscan.com/vulnerability/e648633e-868b-45b2-870a-308a2f9cb7f5 - (MISC) https://wpscan.com/vulnerability/e648633e-868b-45b2-870a-308a2f9cb7f5 - Exploit, Third Party Advisory

11 Jul 2022, 13:40

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-11 13:15

Updated : 2024-11-21 06:41


NVD link : CVE-2022-1757

Mitre link : CVE-2022-1757

CVE.ORG link : CVE-2022-1757


JSON object : View

Products Affected

pagebar_project

  • pagebar
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-352

Cross-Site Request Forgery (CSRF)