Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2546

Опубликовано: 02 фев. 2023
Источник: nvd
CVSS3: 4.7
EPSS Средний

Описание

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:servmask:all-in-one_wp_migration:*:*:*:*:*:wordpress:*:*
Версия до 7.63 (исключая)

EPSS

Процентиль: 98%
0.47815
Средний

4.7 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.7
github
около 3 лет назад

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

EPSS

Процентиль: 98%
0.47815
Средний

4.7 Medium

CVSS3

Дефекты