CVE-2022-0989 Vulnerability Details
/
/
/
CVE-2022-0989 Metadata Quick Info
CVE Published: 11/04/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022
Source: WPScan |
Vendor: Unknown |
Product: NS WooCommerce Watermark
Status : PUBLISHED
CVE-2022-0989 Description
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-80
CWE Name: CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).