2024-07-14 02:06:08 +00:00

108 lines
4.0 KiB
JSON

{
"id": "CVE-2022-3144",
"sourceIdentifier": "security@wordfence.com",
"published": "2022-09-23T14:15:12.900",
"lastModified": "2024-01-11T09:15:46.063",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Wordfence Security \u2013 Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version."
},
{
"lang": "es",
"value": "El plugin Wordfence Security - Firewall & Malware Scan para WordPress es vulnerable a un ataque de tipo Cross-Site Scripting Almacenado en versiones hasta 7.6.0 incluy\u00e9ndola, por medio de una configuraci\u00f3n en la p\u00e1gina de opciones debido a un escape insuficiente en el valor almacenado. Esto hace posible que usuarios autenticados, con privilegios administrativos, inyecten scripts web maliciosos en la configuraci\u00f3n que es ejecutada cada vez que un usuario accede a una p\u00e1gina que muestra la configuraci\u00f3n afectada en los sitios que ejecutan una versi\u00f3n vulnerable."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 4.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.7,
"impactScore": 2.7
},
{
"source": "security@wordfence.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 4.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.3,
"impactScore": 2.7
}
]
},
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:wordfence:wordfence_security:*:*:*:*:*:wordpress:*:*",
"versionEndIncluding": "7.6.0",
"matchCriteriaId": "FBBE93A3-2A94-4965-BDE1-3D19B2DB8777"
}
]
}
]
}
],
"references": [
{
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2780937%40wordfence&new=2780937%40wordfence&sfp_email=&sfph_mail=",
"source": "security@wordfence.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://wordpress.org/plugins/wordfence/#developers",
"source": "security@wordfence.com",
"tags": [
"Release Notes"
]
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/833eb481-4fb4-432e-8e93-3f497ccbf1eb?source=cve",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-3144",
"source": "security@wordfence.com",
"tags": [
"Third Party Advisory"
]
}
]
}