CVE-2022-0346
Google XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting
Record summary
CVE-2022-0346 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 2, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
XML Sitemap Generator for Google | CVE List | 2.0.4 to < 2.0.4 | affected |
xml_sitemap_generatorBrowse xmlsitemapgenerator / xml_sitemap_generator | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code ExecutionCVSS 6.1
WordPress XML Sitemap Generator for Google plugin before 2.0.4 contains a cross-site scripting vulnerability that can lead to remote code execution. It does not validate a parameter which can be set to an arbitrary value, thus causing cross-site scripting via error message or remote code execution if allow_url_include is turned on.
Impact
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the affected system or inject malicious scripts into web pages viewed by users.
Remediation
Update the WordPress XML Sitemap Generator for Google plugin to version 2.0.4 or later to mitigate the XSS and RCE vulnerabilities.
Source: ProjectDiscovery