CVE-2022-0953

CVE-2022-0953: Anti-Malware Security and Brute-Force Firewall < 4.20.96 - Reflected Cross-Site Scripting

Vendor Unknown
Product Anti-Malware Security and Brute-Force Firewall
Weakness CWE-79 · XSS
Published April 25, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

Key dates

02Disclosure timeline

April 25, 2022 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE