CVE-2022-2443
FreeMind WP Browser <= 1.2 - Cross-Site Request Forgery to Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
El plugin FreeMind WP Browser para WordPress es vulnerable a un ataque de tipo Cross-Site Request Forgery en versiones hasta 1.2 incluyéndola. Esto es debido a una falta de protección nonce en la función FreemindOptions() que es encontrada en el archivo ~/freemind-wp-browser.php. Esto hace posible que atacantes no autenticados inyecten scripts web maliciosos en la página, lo que les permite engañar al administrador del sitio para que lleve a cabo una acción como hacer clic en un enlace
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-05 CVE Published
- 2022-07-15 CVE Reserved
- 2024-02-23 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freemind Wp Browser Project Search vendor "Freemind Wp Browser Project" | Freemind Wp Browser Search vendor "Freemind Wp Browser Project" for product "Freemind Wp Browser" | <= 1.2 Search vendor "Freemind Wp Browser Project" for product "Freemind Wp Browser" and version " <= 1.2" | wordpress |
Affected
|