cve/2022/CVE-2022-0214.md

18 lines
843 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-0214](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0214)
![](https://img.shields.io/static/v1?label=Product&message=Popup%20%7C%20Custom%20Popup%20Builder&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%201.3.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-1284%20Improper%20Validation%20of%20Specified%20Quantity%20in%20Input&color=brighgreen)
### Description
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
### POC
#### Reference
- https://wpscan.com/vulnerability/ca2e8feb-15d6-4965-ad9c-8da1bc01e0f4
#### Github
- https://github.com/ARPSyndicate/cvemon