CVE-2022-4897: BackupBuddy < 8.8.3 - Multiple Reflected Cross-Site Scripting
Published Feb 21, 2023
·Updated
The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Affected Software
1 affected component
iThemes Backupbuddy Wordpress<8.8.3
Event History
Feb 21, 2023
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-4897.
2
What is the severity of CVE-2022-4897?
The severity of CVE-2022-4897 is medium.
3
What is the affected software?
The affected software is the BackupBuddy WordPress plugin version up to 8.8.3.
4
What is the vulnerability type of CVE-2022-4897?
CVE-2022-4897 is a Reflected Cross-Site Scripting (XSS) vulnerability.
5
Is there a fix available for CVE-2022-4897?
Yes, upgrading to version 8.8.3 of the BackupBuddy WordPress plugin fixes CVE-2022-4897.