PT-2020-6784 · Unknown · Beaver Builder

Zhouyuan Yang

·

Published

2020-06-05

·

Updated

2022-09-13

·

CVE-2022-2695

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Beaver Builder versions up to, and including, 2.5.5.2
Description The issue arises from insufficient input sanitization and output escaping of the caption parameter when uploading media files through the Beaver Builder editor. This allows authenticated attackers to inject arbitrary web scripts into pages, which will execute when a user accesses the injected page. The vulnerability can be exploited by remote attackers to perform cross-site scripting attacks.
Recommendations For versions up to, and including, 2.5.5.2, update to a version that addresses the insufficient input sanitization and output escaping of the caption parameter to prevent cross-site scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-06384
CVE-2022-2695

Affected Products

Beaver Builder