CVE-2022-3919

Published: Dic 12, 2022 Last Modified: Apr 22, 2025 EU-VD ID: EUVD-2022-43254 Aliases: GSD-2022-3919
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,8
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none

Description

AI Translation Available

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0021
Percentile
0,4th
Updated

EPSS Score Trend (Last 91 Days)

Application

Jetpack Crm by Automattic

Version Range Affected
To 5.4.3 (exclusive)
cpe:2.3:a:automattic:jetpack_crm:*:*:*:*:*:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://wpscan.com/vulnerability/fe2f1d52-8421-4b46-b829-6953a0472dcb
https://wpscan.com/vulnerability/fe2f1d52-8421-4b46-b829-6953a0472dcb