CVE-2022-1985Cross-site Scripting in Download Manager

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateJun 14

Description

The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w8hq-x2cx-c5vh: The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 32022-06-14
CVEList
Download Manager <= 3.2.42 - Reflected Cross-Site Scripting2022-06-13
CVE-2022-1985 — Cross-site Scripting | cvebase