CVE-2022-1209 Vulnerability Details

  /     /     /  

CVE-2022-1209 Metadata Quick Info

CVE Published: 10/05/2022 | CVE Updated: 02/08/2024 | CVE Year: 2022
Source: Wordfence | Vendor: ultimatemember | Product: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Status : PUBLISHED

CVE-2022-1209 Description

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

Metrics

CVSS Version: 3.1 | Base Score: 4.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: CWE-601 URL Redirection to Untrusted Site ( Open Redirect )
Source: ultimatemember

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).