🔙 목록으로 돌아가기

CVE-2022-0218: HTML Email Template Designer < 3.1 - Stored Cross-Site Scripting

TitleHTML Email Template Designer < 3.1 - Stored Cross-Site Scripting
Authorhexcat
SeverityMedium
ImpactAn attacker can exploit this vulnerability to inject malicious scripts into the subject field of an email template, potentially leading to unauthorized access, data theft, or further compromise of the affected system.
RemediationUpdate to version 3.1 or later of the HTML Email Template Designer plugin to fix the vulnerability.
CVSS Score6.1
EPSS Score0.62403
CVE IDCVE-2022-0218
CWE IDCWE-79
Tags cve cve2022 wordpress wp-plugin xss codemiq vkev vuln

🔍 Vulnerability Description

WordPress Email Template Designer WP HTML Mail allows stored cross-site scripting through an unprotected REST-API endpoint.

🌐 HTTP Request

GET /index.php?rest_route=/whm/v3/themesettings HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Version/16.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0218.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0218.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A