CVE Feed

    Dashboard / CVE / CVE-2022-1618

    CVE-2022-1618

    The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads

    Published:Jan 16, 2024
    Last Modified:Nov 21, 2024
    EPS:Jan 16, 2024
    EPSS Score:0.002
    CVSS Score:6.1

    Affected Products

    Vendor
    Marcorulicke
    Product
    Coru Lfmember

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High