CVE-2022-4663

The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an imported CSV file in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a site's administrator into uploading a CSV file with the malicious payload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:youngtechleads:members_import:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:35

Type Values Removed Values Added
Summary
  • (es) El complemento Members Import para WordPress es vulnerable a Self Cross-Site Scripting a través del parámetro user_login en un archivo CSV importado en versiones hasta la 1.4.2 incluida debido a una limpieza de entrada y un escape de salida insuficientes. Esto hace posible que los atacantes inyecten scripts web arbitrarios en páginas que se ejecutan si pueden engañar con éxito al administrador de un sitio para que cargue un archivo CSV con la carga maliciosa.
References () https://plugins.trac.wordpress.org/browser/members-import/trunk/members-import.php#L113 - Exploit, Third Party Advisory () https://plugins.trac.wordpress.org/browser/members-import/trunk/members-import.php#L113 - Exploit, Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/3abbc407-f660-4b1f-9d48-436320e5fdd7 - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/3abbc407-f660-4b1f-9d48-436320e5fdd7 - Third Party Advisory
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 5.5

Information

Published : 2023-01-03 14:15

Updated : 2024-11-21 07:35


NVD link : CVE-2022-4663

Mitre link : CVE-2022-4663

CVE.ORG link : CVE-2022-4663


JSON object : View

Products Affected

youngtechleads

  • members_import
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')