PoC Index

CVE-2022-0385

MEDIUM 6.1EPSS 1.4%

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.40% chance of exploitation in the next 30 days, 71th percentile
Published
2022-02-28
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related