4.8
CVE-2022-3832
- EPSS 0.47%
- Veröffentlicht 19.12.2022 14:15:10
- Zuletzt bearbeitet 17.04.2025 15:15:46
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
External Media < 1.0.36 - Admin+ Stored XSS
External Media <= 1.0.35 - Authenticated (Administrator+) Stored Cross-Site Scripting
The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Mögliche Gegenmaßnahme
External Media: Update to version 1.0.36, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
External Media Project ≫ External Media SwPlatformwordpress Version < 1.0.36
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
External Media
Version
*-1.0.35
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.369 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
https://wpscan.com/vulnerability/458ec2fd-4175-4cb4-b334-b63f6e643b92
https://www.wordfence.com/threat-intel/vulnerabilities/id/c2121162-68db-47c4-80f6-222f013f48c2