CVE-2022-3137: TaskBuilder < 1.0.8 - Subscriber+ Stored XSS via SVG file upload
Published Oct 10, 2022
·Updated
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
Affected Software
1 affected component
Taskbuilder Taskbuilder WordPress<1.0.8
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3137?
CVE-2022-3137 has a medium severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2022-3137?
To fix CVE-2022-3137, update the Taskbuilder WordPress plugin to version 1.0.8 or later.
3
Who is affected by CVE-2022-3137?
CVE-2022-3137 affects any site using the Taskbuilder WordPress plugin before version 1.0.8.
4
What type of attack does CVE-2022-3137 enable?
CVE-2022-3137 enables stored cross-site scripting attacks via malicious SVG file uploads.
5
What actions can authenticated users take regarding CVE-2022-3137?
Authenticated users, including subscribers, can create tasks that may exploit CVE-2022-3137 through file attachments.