Record summary

CVE-2022-0780 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

SearchIQ – The Search Solution

CVE List3.9 to < 3.9affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-0780Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 812 B

GitHub

PoC details
GitHubCVE-2022-0780Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 812 B

GitHub

PoC details

References

2