PT-2022-18886 · Cleantalk · Cleantalk Antispam

Ramuel Gall

·

Published

2022-04-19

·

Updated

2022-04-28

·

CVE-2022-28222

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CleanTalk AntiSpam plugin versions <= 5.173
Description The issue concerns a Reflected Cross-Site Scripting (XSS) vulnerability. It can be exploited via the page parameter in the /lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php file.
Recommendations For CleanTalk AntiSpam plugin versions <= 5.173, consider updating to a version that contains a fix for this issue. As a temporary workaround, restrict access to the /lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php file to minimize the risk of exploitation. Avoid using the page parameter in the affected file until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28222

Affected Products

Cleantalk Antispam