Lucene search

K
cve[email protected]CVE-2022-42460
HistoryNov 10, 2022 - 10:15 p.m.

CVE-2022-42460

2022-11-1022:15:15
CWE-264
CWE-79
web.nvd.nist.gov
35
7
cve
2022
42460
broken access control
stored cross-site scripting
xss
traffic manager plugin
wordpress

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

19.6%

Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.

Affected configurations

Vulners
NVD
Node
sedlextraffic_managerRange1.4.5
VendorProductVersionCPE
sedlextraffic_manager*cpe:2.3:a:sedlex:traffic_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "SedLex",
    "product": "Traffic Manager (WordPress plugin)",
    "versions": [
      {
        "version": "<= 1.4.5",
        "status": "affected",
        "lessThanOrEqual": "1.4.5",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

19.6%

Related for CVE-2022-42460