CVE-2022-2844: MotoPress Timetable and Event Schedule Calendar cross site scripting
A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvcid=1&cpmvcdoaction=mvparse&f=datafeed&calid=1&monthindex=1&method=adddetails&id=2 of the component Calendar Handler. The manipulation of the argument Subject/Location/Description leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206487.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2844?
The severity of CVE-2022-2844 is medium with a CVSS score of 6.1.
Which software version is affected by CVE-2022-2844?
The Motopress Timetable and Event Schedule version up to 1.4.06 is affected by CVE-2022-2844.
What is the vulnerability type for CVE-2022-2844?
CVE-2022-2844 is classified as a problematic vulnerability.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-2844?
CVE-2022-2844 is associated with CWE ID 79.
How can I fix CVE-2022-2844?
To fix CVE-2022-2844, it is recommended to update the MotoPress Timetable and Event Schedule component to a version higher than 1.4.06.