Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
* Fix: CVE-2022-4321

* added metadata

---------

Co-authored-by: rivers <[email protected]>
Co-authored-by: sandeep <[email protected]>
  • Loading branch information
3 people authored Oct 8, 2023
1 parent 6b3707c commit aea032a
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion http/cves/2022/CVE-2022-4321.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ id: CVE-2022-4321

info:
name: PDF Generator for WordPress < 1.1.2 - Cross Site Scripting
author: r3Y3r53
author: r3Y3r53,HuTa0
severity: medium
description: |
The plugin includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Expand All @@ -25,6 +25,7 @@ info:
vendor: wpswings
product: pdf_generator_for_wordpress
framework: wordpress
publicwww-query: "/wp-content/plugins/pdf-generator-for-wp"
tags: cve,cve2022,wpscan,wordpress,wp,wp-plugin,xss,pdf-generator-for-wp

http:
Expand All @@ -39,6 +40,7 @@ http:
words:
- '><script>alert(document.domain)</script>'
- 'pdf-generator-for-wp'
- 'Total execution time is'
condition: and

- type: word
Expand Down

0 comments on commit aea032a

Please sign in to comment.