.. / CVE-2022-0899

Exploit for Header Footer Code Manager < 1.1.24 - Cross-Site Scripting (CVE-2022-0899)

Description:

The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

Nuclei Template

View the template here CVE-2022-0899.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0899.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-0899
https://wpscan.com/vulnerability/1772417a-1abb-4d97-9694-1254840defd1