CVE-2022-4545 – Sitemap < 4.4 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2022-4545
The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. El complemento Sitemap de WordPress anterior a 4.4 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían usarse contra usuarios con privilegios elevados, como administradores. The Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://wpscan.com/vulnerability/19f482cb-fcfd-43e6-9a04-143e06351a70 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-0952 – Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
https://notcve.org/view.php?id=CVE-2022-0952
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog. El plugin Sitemap by click5 de WordPress versiones anteriores a 1.0.36, no dispone de comprobaciones de autorización y de tipo CSRF cuando son actualizadas las opciones por medio de un endpoint REST, y no es asegurado de que la opción que va a actualizarse pertenezca al plugin. Como resultado, atacantes no autenticados podrían cambiar opciones arbitrarias del blog, como users_can_register y default_role, permitiéndoles crear una nueva cuenta de administrador y tomar el control del blog • https://github.com/RandomRobbieBF/CVE-2022-0952 https://wpscan.com/vulnerability/0f694961-afab-44f9-846c-e80a0f6c768b • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •
CVE-2021-24192 – Tree Sitemap < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
https://notcve.org/view.php?id=CVE-2021-24192
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE. Unos usuarios poco privilegiados pueden usar la acción AJAX "cp_plugins_do_button_job_later_callback" en el plugin de WordPress Tree Sitemap, versiones anteriores a 2.9, para instalar cualquier plugin (incluyendo una versión específica) del repositorio de WordPress, así como desencadenar un plugin arbitrario desde el blog, que ayuda a los atacantes a instalar plugins vulnerables y podría conllevar a vulnerabilidades más críticas como una RCE • https://wpscan.com/vulnerability/74889e29-5349-43d1-baf5-1622493be90c • CWE-285: Improper Authorization •
CVE-2006-3749 – Mambo Component Sitemap 2.0.0 - Remote File Inclusion
https://notcve.org/view.php?id=CVE-2006-3749
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. Vulnerabilidad de inclusión remota de archivo en PHP en sitemap.xml.php en Sitemap component (com_sitemap) 2.0.0 para Mambo 4.5.1 CMS, cuando register_globals está habiliado, permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro mosConfig_absolute_path. • https://www.exploit-db.com/exploits/2028 http://advisories.echo.or.id/adv/adv38-matdhule-2006.txt http://archives.neohapsis.com/archives/bugtraq/2006-07/0180.html http://secunia.com/advisories/21055 http://securityreason.com/securityalert/1249 http://www.securityfocus.com/bid/18991 http://www.securityfocus.com/bid/24592 http://www.vupen.com/english/advisories/2006/2803 https://exchange.xforce.ibmcloud.com/vulnerabilities/27723 • CWE-94: Improper Control of Generation of Code ('Code Injection') •