7.5
CVE-2022-0989
- EPSS 1.19%
- Veröffentlicht 11.04.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:48
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality
NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
Mögliche Gegenmaßnahme
NS Watermark For WooCommerce: Update to version 3.0.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nsthemes ≫ Ns Watermark For Woocommerce SwPlatformwordpress Version <= 2.11.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
NS Watermark For WooCommerce
Version
*-2.11.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.19% | 0.638 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
https://wpscan.com/vulnerability/a6bfc150-8e3f-4b2d-a6e1-09406af41dd4
https://www.wordfence.com/threat-intel/vulnerabilities/id/9d17f26b-e8b7-480d-bf03-2cfdb261fa28