PT-2022-19595 · Adam Skaat · Countdown & Clock

Re-Alter

+1

·

Published

2022-05-06

·

Updated

2022-05-16

·

CVE-2022-29422

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Adam Skaat's Countdown & Clock plugin versions prior to 2.3.3
Description The issue concerns Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities. These vulnerabilities can be exploited via several vulnerable parameters, including &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-left, &ycd-circle-countdown-before-countdown, and &ycd-circle-countdown-after-countdown.
Recommendations For Adam Skaat's Countdown & Clock plugin versions prior to 2.3.3, update to version 2.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using the vulnerable parameters in the plugin's configuration until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29422

Affected Products

Countdown & Clock