Record summary

CVE-2022-0385 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Crazy Bone

CVE List0.6.0 to ≤ 0.6.0affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-0385Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 638 B

GitHub

PoC details
GitHubCVE-2022-0385Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 638 B

GitHub

PoC details

References

2