The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15534 | The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:25:40.210Z
Reserved: 2022-01-26T00:00:00
Link: CVE-2022-0385
No data.
Status : Modified
Published: 2022-02-28T09:15:09.197
Modified: 2024-11-21T06:38:30.750
Link: CVE-2022-0385
No data.
OpenCVE Enrichment
No data.
EUVD