CVE-2022-42460

Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sedlex:traffic_manager:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 6.5
References () https://patchstack.com/database/vulnerability/traffic-manager/wordpress-traffic-manager-plugin-1-4-5-broken-access-control-vulnerability-leading-to-stored-cross-site-scripting-xss?_s_id=cve - Third Party Advisory () https://patchstack.com/database/vulnerability/traffic-manager/wordpress-traffic-manager-plugin-1-4-5-broken-access-control-vulnerability-leading-to-stored-cross-site-scripting-xss?_s_id=cve - Third Party Advisory
References () https://wordpress.org/plugins/traffic-manager/ - Product, Third Party Advisory () https://wordpress.org/plugins/traffic-manager/ - Product, Third Party Advisory

06 Jul 2023, 14:42

Type Values Removed Values Added
CWE CWE-79 NVD-CWE-Other

Information

Published : 2022-11-10 22:15

Updated : 2024-11-21 07:25


NVD link : CVE-2022-42460

Mitre link : CVE-2022-42460

CVE.ORG link : CVE-2022-42460


JSON object : View

Products Affected

sedlex

  • traffic_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-264

Permissions, Privileges, and Access Controls

NVD-CWE-Other