5.4

CVE-2022-4756

Exploit

YouTube Channel < 3.23.0 - Contributor+ Stored XSS via Shortcode

YouTube Channel < 3.0.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Mögliche Gegenmaßnahme
My YouTube Channel: Update to version 3.23.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
My Youtube Channel ProjectMy Youtube Channel SwPlatformwordpress Version < 3.23.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt My YouTube Channel
Version *-3.0.12.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.442
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/d67b0f7a-fdb1-4305-9976-c5f77b0e3b61
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/86e62a7d-53d6-40c8-823d-811cfb3d75b2
Third Party Advisory