Classified Listing Pro < 2.0.20 - Reflected Cross-Site Scripting
CVE-2022-2655
6.1MEDIUM
Summary
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected Version(s)
Classified Listing Pro - Classified ads & Business Directory Plugin 2.0.20
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Team ISH Tecnologia (Thiago Martins
Jorge Buzeti
Leandro Inacio
Lucas de Souza
Matheus Oliveira
Filipe Baptistella
Leonardo Paiva
Jose Thomaz
Joao Maciel
Vinicius Pereira
Geovanni Campos
Hudson Nowak
Guilherme Acerbi) and Islan Ferreira.