PT-2022-23663 · Unknown · Smarttagplugin

Martin Heyden

·

Published

2022-09-09

·

Updated

2023-06-27

·

CVE-2022-36859

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SmartTagPlugin versions prior to 1.2.21-6
Description The issue is related to improper input validation in the SmartTagPlugin, allowing privileged attackers to trigger a cross-site scripting (XSS) attack on a victim's devices.
Recommendations For versions prior to 1.2.21-6, update to version 1.2.21-6 or later to resolve the issue. As a temporary workaround, consider restricting access to the SmartTagPlugin to minimize the risk of exploitation.

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-36859

Affected Products

Smarttagplugin