CVE-2022-3137
Description
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
CWE
- CWE-79 — CWE-79 Cross-Site Scripting (XSS)
Affected
- Unknown / Taskbuilder – WordPress Project & Task Management plugin — v=1.0.8 <1.0.8 [affected]
CVSS
- (none)
References
Source
cvelistV5-main/cves/2022/3xxx/CVE-2022-3137.json