Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2022-1618
HistoryJan 16, 2024 - 3:52 p.m.

CVE-2022-1618 Coru LFMember <= 1.0.2 - Stored Cross-Site Scripting via CSRF

2024-01-1615:52:50
WPScan
github.com
1
coru lfmember
stored cross-site scripting
csrf
wordpress plugin
csrf check
sanitisation
escaping
admin
xss payloads

AI Score

6.1

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads

AI Score

6.1

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2022-1618