CVE-2022-3137
TaskBuilder < 1.0.8 - Subscriber+ Stored XSS via SVG file upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
| CWE | CWE-79 |
| Vendor | unknown |
| Product | taskbuilder – wordpress project & task management plugin |
| Published | Oct 10, 2022 |
| Last Updated | Aug 3, 2024 |
Stay Ahead of the Next One
Get instant alerts for unknown taskbuilder – wordpress project & task management plugin
Be the first to know when new unknown vulnerabilities affecting unknown taskbuilder – wordpress project & task management plugin are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Taskbuilder – WordPress Project & Task Management plugin
1.0.8 < 1.0.8
References
Credits
Rizacan Tufan