CVE-2022-50948: Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting
Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which execute in the browser when visitors access the accommodations page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50948?
CVE-2022-50948 is classified as a moderate severity stored cross-site scripting vulnerability.
How do I fix CVE-2022-50948?
To mitigate CVE-2022-50948, upgrade to a patched version of Motopress Hotel Booking Lite that resolves the XSS vulnerability.
Who is affected by CVE-2022-50948?
CVE-2022-50948 affects users of Motopress Hotel Booking Lite version 4.2.4.
What impact does CVE-2022-50948 have on users?
CVE-2022-50948 allows authenticated attackers to inject malicious scripts into accommodation type fields, potentially compromising user data.
What should I do if I can't upgrade due to CVE-2022-50948?
If unable to upgrade, consider implementing input validation and sanitization measures to mitigate the risk posed by CVE-2022-50948.