CVE-2022-45821: WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)
Published Aug 8, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.
Affected Software
1 affected component
NooTheme Noo Timetable Wordpress<=2.1.3
Event History
Aug 8, 2023
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-45821?
CVE-2022-45821 has a medium severity rating due to its potential impact on users through stored Cross-Site Scripting (XSS).
2
How do I fix CVE-2022-45821?
To fix CVE-2022-45821, update the Noo Timetable plugin to version 2.1.4 or later, which resolves the vulnerability.
3
What types of attacks are possible with CVE-2022-45821?
CVE-2022-45821 allows attackers to execute arbitrary JavaScript in the context of the affected application, potentially leading to data theft and session hijacking.
4
Which versions of the Noo Timetable plugin are affected by CVE-2022-45821?
CVE-2022-45821 affects all versions of the Noo Timetable plugin up to and including 2.1.3.
5
Is authentication required to exploit CVE-2022-45821?
Yes, CVE-2022-45821 requires authentication as it is a stored XSS vulnerability that affects contributors and above.