2024-12-08 03:06:42 +00:00

90 lines
2.7 KiB
JSON

{
"id": "CVE-2021-4227",
"sourceIdentifier": "contact@wpscan.com",
"published": "2024-01-16T16:15:09.270",
"lastModified": "2024-11-21T06:37:11.290",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section"
},
{
"lang": "es",
"value": "El complemento de WordPress ark-commenteditor hasta la versi\u00f3n 2.15.6 no sanitiza ni codifica adecuadamente los comentarios cuando est\u00e1 en el editor de c\u00f3digo fuente, lo que permite a los atacantes inyectar un iFrame en la p\u00e1gina y, por lo tanto, cargar contenido arbitrario desde cualquier p\u00e1gina a la secci\u00f3n de comentarios."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:obg:ark_wysiwyg_comment_editor:*:*:*:*:*:wordpress:*:*",
"versionEndIncluding": "2.15.6",
"matchCriteriaId": "0D7DDA5E-7004-48F6-A6E7-4D283878B1DE"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/8d015eba-31dc-44cb-a051-4e95df782b75/",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://wpscan.com/vulnerability/8d015eba-31dc-44cb-a051-4e95df782b75/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}