Crazy Bone <= 0.6.0 - Unauthenticated Stored XSS
CVE-2022-0385

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 February 2022

Summary

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

Affected Version(s)

Crazy Bone 0.6.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.