ZeroHour

CVE-2022-0385

PoC
CVSS 3.1
6.1 medium
EPSS
1%p71
Published
()
Modified
Description

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

Vendors
crazy bone project
Products
crazy bone
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.