2024-12-15 03:03:56 +00:00

94 lines
2.8 KiB
JSON

{
"id": "CVE-2022-2375",
"sourceIdentifier": "contact@wpscan.com",
"published": "2022-08-22T15:15:14.677",
"lastModified": "2024-11-21T07:00:51.963",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues"
},
{
"lang": "es",
"value": "El plugin WP Sticky Button de WordPress versiones anteriores a 1.4.1, no dispone de comprobaciones de autorizaci\u00f3n y de tipo CSRF cuando guarda sus configuraciones, lo que permite a usuarios no autenticados actualizarlas. Adem\u00e1s, debido a una falta de escapes en algunos de ellos, podr\u00eda conllevar a problemas de tipo Cross-Site Scripting Almacenado"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "contact@wpscan.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
},
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:okapitech:wp_sticky_button:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "1.4.1",
"matchCriteriaId": "2D6674C2-654C-4AA0-AF70-314B9624FDE5"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/caab1fca-cc6b-45bb-bd0d-f857edd8bb81",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://wpscan.com/vulnerability/caab1fca-cc6b-45bb-bd0d-f857edd8bb81",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}