PT-2020-6782 · Unknown · Beaver Builder

Zhouyuan Yang

·

Published

2020-06-05

·

Updated

2022-09-13

·

CVE-2022-2517

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Beaver Builder versions up to, and including, 2.5.5.2
Description The issue arises from insufficient input sanitization and output escaping in the 'Caption - On Hover' value associated with images. This allows authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages, which will execute whenever a user accesses an injected page. The vulnerability can be exploited by remote attackers to perform cross-site scripting attacks.
Recommendations For versions up to, and including, 2.5.5.2, update to a version later than 2.5.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the Beaver Builder editor to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-06379
CVE-2022-2517

Affected Products

Beaver Builder