CVE-2022-4011
Simple History Plugin Header neutralization for logs
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213785 was assigned to this vulnerability.
Se encontró una vulnerabilidad en el complemento de Simple History. Ha sido calificado como crítico. Este problema afecta un procesamiento desconocido del componente Header Handler. La manipulación del argumento X-Forwarded-For conduce a una neutralización de salida inadecuada para los registros. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-213785.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-16 CVE Reserved
- 2022-11-16 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-116: Improper Encoding or Escaping of Output
- CWE-707: Improper Neutralization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://drive.google.com/file/d/142cPciqIhNbfKhhxIwbrYFTegLvnwin_/view | 2024-08-03 | |
https://drive.google.com/file/d/1AJXip8UG_ADbxtokPzAb61-lEg-xLebZ/view | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simple History Project Search vendor "Simple History Project" | Simple History Search vendor "Simple History Project" for product "Simple History" | - | wordpress |
Affected
|