Record summary

CVE-2022-45365 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.23.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMStock Ticker <= 3.23.2 - Cross-Site-ScriptingCVSS 6.1

The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_symbol_search_test function in versions up to, and including, 3.23.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Impact

Unauthenticated attackers can inject malicious JavaScript through the endpoint parameter in the ajax_stockticker_symbol_search_test function to steal WordPress user session cookies and credentials.

Remediation

Fixed in version 3.23.3

WeaknessesCWE-79
Authorstheamanrawat
Template tagscve2022cvewordpresswp-pluginwpscanwpstock-tickerunauthxssurosevicvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:urosevic:stock_ticker:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/stock-ticker/
FOFA: body=/wp-content/plugins/stock-ticker/

Source: ProjectDiscovery

References

2