nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0385 CVE-2022-0385
MEDIUM
Crazy Bone <= 0.6.0 - Unauthenticated Stored XSS
Record summary
CVE-2022-0385 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Crazy Bone | CVE List | 0.6.0 to ≤ 0.6.0 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2022-0385Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2022-0385Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/60067b8b-9fa5-40d1-817a-929779947891