CVE-2022-2846

The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dwbooster:calendar_event_multi_view:*:*:*:*:*:wordpress:*:*

History

05 Apr 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/171697/Calendar-Event-Multi-View-1.4.07-Cross-Site-Scripting.html -
CWE CWE-352 CWE-79

06 Oct 2022, 16:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:dwbooster:calendar_event_multi_view:-:*:*:*:*:wordpress:*:* cpe:2.3:a:dwbooster:calendar_event_multi_view:*:*:*:*:*:wordpress:*:*
CWE CWE-79 CWE-352
References (MISC) https://wpscan.com/vulnerability/95f92062-08ce-478a-a2bc-6d026adf657c - (MISC) https://wpscan.com/vulnerability/95f92062-08ce-478a-a2bc-6d026adf657c - Exploit, Third Party Advisory

03 Oct 2022, 14:15

Type Values Removed Values Added
CWE CWE-352 CWE-79
CWE-862
References
  • {'url': 'https://vuldb.com/?id.206488', 'name': 'https://vuldb.com/?id.206488', 'tags': ['Third Party Advisory', 'VDB Entry'], 'refsource': 'MISC'}
  • (MISC) https://wpscan.com/vulnerability/95f92062-08ce-478a-a2bc-6d026adf657c -
Summary A vulnerability classified as problematic was found in Calendar Event Multi View Plugin. This vulnerability affects unknown code of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The identifier of this vulnerability is VDB-206488. The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.

17 Aug 2022, 14:56

Type Values Removed Values Added
First Time Dwbooster
Dwbooster calendar Event Multi View
References (MISC) https://vuldb.com/?id.206488 - (MISC) https://vuldb.com/?id.206488 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:dwbooster:calendar_event_multi_view:-:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

16 Aug 2022, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-16 19:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-2846

Mitre link : CVE-2022-2846

CVE.ORG link : CVE-2022-2846


JSON object : View

Products Affected

dwbooster

  • calendar_event_multi_view
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-862

Missing Authorization

CWE-352

Cross-Site Request Forgery (CSRF)