PT-2022-7082 · WordPress · Mapping Multiple Urls Redirect Same Page

Ran Crane

·

Published

2022-03-01

·

Updated

2022-03-31

·

CVE-2022-0599

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8
Description The issue exists due to the lack of protection measures for the web page structure, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. Specifically, the plugin does not sanitize and escape the mmursp id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Recommendations For Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8, consider disabling the plugin until a patch is available to prevent exploitation. As a temporary workaround, restrict access to the admin page where the mmursp id parameter is output to minimize the risk of exploitation. Avoid using the mmursp id parameter in the affected admin page until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07527
CVE-2022-0599

Affected Products

Mapping Multiple Urls Redirect Same Page