Lucene search

K
cveWordfenceCVE-2022-4410
HistoryDec 14, 2022 - 10:15 p.m.

CVE-2022-4410

2022-12-1422:15:11
CWE-79
Wordfence
web.nvd.nist.gov
29
permalink manager lite
wordpress
cve-2022-4410
cross-site scripting
nvd
security vulnerability

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

19.6%

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 2.2.20.3 due to improper output escaping on post/page/media titles. This makes it possible for attackers to inject arbitrary web scripts on the permalink-manager page if another plugin or theme is installed on the site that allows lower privileged users with unfiltered_html the ability to modify post/page titles with malicious web scripts.

Affected configurations

Nvd
Vulners
Node
permalink_manager_lite_projectpermalink_manager_liteRange2.2.20.3wordpress
VendorProductVersionCPE
permalink_manager_lite_projectpermalink_manager_lite*cpe:2.3:a:permalink_manager_lite_project:permalink_manager_lite:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "mbis",
    "product": "Permalink Manager Lite",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.2.20.3",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

19.6%

Related for CVE-2022-4410