PT-2022-7082 · WordPress · Mapping Multiple Urls Redirect Same Page
Ran Crane
·
Published
2022-03-01
·
Updated
2022-03-31
·
CVE-2022-0599
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8
Description
The issue exists due to the lack of protection measures for the web page structure, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. Specifically, the plugin does not sanitize and escape the
mmursp id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.Recommendations
For Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8, consider disabling the plugin until a patch is available to prevent exploitation. As a temporary workaround, restrict access to the admin page where the
mmursp id parameter is output to minimize the risk of exploitation. Avoid using the mmursp id parameter in the affected admin page until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mapping Multiple Urls Redirect Same Page