5.4

CVE-2022-2299

Exploit

Allow SVG Files <= 1.1 - Author+ Stored Cross Site Scripting via SVG

Allow SVG Files <= 1.1 - Authenticated (Author+) Stored Cross-Site Scripting

The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
Mögliche Gegenmaßnahme
Allow svg files: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Allow Svg Files ProjectAllow Svg Files Version1.0 SwPlatformwordpress
Allow Svg Files ProjectAllow Svg Files Version1.1 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Allow svg files
Version *-1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.384
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/29015c35-0470-41b8-b197-c71b800ae2a9
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ce57a3eb-a71b-4335-9e6c-52648ce00062
Third Party Advisory