Record summary

CVE-2023-0099 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Simple URLs

Default status: unaffected

CVE ListBefore 115affected

Proofs of concept

1

Repository PoCs

GitHubamirzargham/CVE-2023-0099-exploitRepository PoCby amirzarghamStars: 6Not analyzed2 files

3.4 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMSimple URLs < 115 - Cross Site ScriptingCVSS 6.1

The plugin does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Impact

Successful exploitation of this vulnerability can lead to session hijacking, defacement of websites, theft of sensitive information, and potential remote code execution.

Remediation

Fixed in version 115

WeaknessesCWE-79
Authorsr3Y3r53
Template tagswpscanpacketstormcvecve2023xsssimple-urlsauthenticatedwordpresswpwp-plugingetlassovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:getlasso:simple_urls:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3