CVE-2022-0201
Permalink Manager < 2.2.15 - Reflected Cross-Site Scripting
Record summary
CVE-2022-0201 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Permalink Manager LiteBrowse Maciej Bis / Permalink Manager Lite | CVE List | 2.2.15 to < 2.2.15 | affected |
Permalink Manager ProBrowse Maciej Bis / Permalink Manager Pro | CVE List | 2.2.15 to < 2.2.15 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Permalink Manager <2.2.15 - Cross-Site ScriptingCVSS 6.1
WordPress Permalink Manager Lite and Pro plugins before 2.2.15 contain a reflected cross-site scripting vulnerability. They do not sanitize and escape query parameters before outputting them back in the debug page.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Update to WordPress Permalink Manager version 2.2.15 or later to mitigate the vulnerability.
Source: ProjectDiscovery