MEDIUM
Showing URL in QR Code <= 0.0.1 - Stored XSS via CSRF
Published Nov 28, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.29%
Description
The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin or editor add Stored XSS payloads via a CSRF attack
Affected products
- Vendor n/a Product Showing URL in QR Code Defaultaffected
Affected
- ≥ 0, ≤ 0.0.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Showing URL in QR Code | affected | Affected
|
- 0.0.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- https://bulletin.iese.de/post/get-site-to-phone-by-qr-code_0-0-1/ ExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43187 Advisory
- https://wpscan.com/vulnerability/a70ad549-2e09-44fb-b894-4271ad4a84f6 exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bulletin.iese.de/post/get-site-to-phone-by-qr-code_0-0-1/ | ExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43187 | Advisory | |
| https://wpscan.com/vulnerability/a70ad549-2e09-44fb-b894-4271ad4a84f6 | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Nov 28, 2022
Updated Aug 3, 2024
Reserved Nov 3, 2022
Link CVE-2022-3847
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data