• CVE-2022-4478

发布时间: 2023年2月6日

修改时间: 2023年2月6日

概要

The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVSS v3 指标

NVD openEuler
Confidentiality Low Low
Attack Vector Network Network
CVSS评分 5.4 5.4
Attack Complexity Low Low
Privileges Required Low Low
Scope Changed Changed
Integrity Low Low
User Interaction Required Required
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1035 The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. 2023年2月6日

影响产品

产品 状态
KY3.4-4A fontawesome-fonts Unaffected
KY3.4-5 fontawesome-fonts Unaffected
KY3.5.1 fontawesome-fonts Unaffected
KY3.5.2 fontawesome-fonts Unaffected