6.1

CVE-2022-2311

Exploit

Find and Replace All < 1.3 - Reflected Cross Site Scripting

Find and Replace All <= 1.3 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
Mögliche Gegenmaßnahme
Find and Replace All: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Find And Replace All ProjectFind And Replace All SwPlatformwordpress Version < 1.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Find and Replace All
Version *-1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.38
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/287a14dc-d1fc-481d-84af-7eb172dc68c9
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/7f4f188f-ca84-44df-9738-d61094c2e695
Third Party Advisory