CVE-2022-0399 – Advanced Product Labels for WooCommerce < 1.2.3.7 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-0399
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting El plugin Advanced Product Labels for WooCommerce de WordPress versiones anteriores a 1.2.3.7, no sanea y escapa del parámetro tax_color_set_type antes de devolverlo en la respuesta de la acción AJAX berocket_apl_color_listener, conllevando a un ataque de tipo Cross-Site Scripting Reflejado • https://plugins.trac.wordpress.org/changeset/2678919 https://wpscan.com/vulnerability/5e5fdcf4-ec2b-4e73-8009-05606b2d5164 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •