GHSA-qrqm-574x-q7f2

Suggest an improvement
Source
https://github.com/advisories/GHSA-qrqm-574x-q7f2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-qrqm-574x-q7f2/GHSA-qrqm-574x-q7f2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qrqm-574x-q7f2
Aliases
  • CVE-2022-38073
Published
2022-09-22T00:00:22Z
Modified
2023-11-08T04:10:10.396723Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Awesome Support vulnerable to persistent cross-site scripting
Details

Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.

Database specific
{
    "nvd_published_at": "2022-09-21T20:15:00Z",
    "github_reviewed_at": "2022-09-29T19:06:17Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Packagist / awesome-support/awesome-support

Package

Name
awesome-support/awesome-support
Purl
pkg:composer/awesome-support/awesome-support

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.8

Affected versions

3.*

3.0.0-beta-1
3.0.0-beta-2
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.1.3
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.1.10
3.1.11
3.1.12
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4_RC01
3.3.4_RC02
3.3.4_RC03
3.3.4_RC05
3.3.4
3.4.0_RC01
3.6.0_RC01
3.6.0_RC02
3.6.0_RC04
3.6.0_RC05

4.*

4.0.0_RC01
4.0.0_RC02
4.0.0_RC03
4.0.0_RC04
4.0.0_RC05
4.0.0_RC06
4.0.0_RC07
4.0.0_RC08
4.0.0_RC09
4.0.0_RC10
4.0.0_RC11
4.0.0
4.0.2
4.0.3
4.0.4
4.0.5_RC01
4.0.5_RC02
4.0.5_RC03
4.0.5_RC04
4.0.5
4.0.6
4.1.0
4.2.0
4.2.1
4.3.0
4.3.1
4.3.2
4.3.4
4.3.5
4.4.0_RC01
4.4.0_RC02
4.4.0_RC03
4.4.0_RC04
4.4.0_RC05
4.4.0_RC06
4.4.0_RC07
4.4.0_RC08
4.4.0_RC09
4.4.0_RC10
4.4.0_RC11
4.4.0_RC12

5.*

5.0.0
5.1.0
5.1.1
5.2_RC10
5.2.0_RC11
5.2.0_RC13
5.2.0_RC14
5.2.0_RC16
5.2.0_RC17
5.2.0_RC18
5.2.0_RC19
5.2.0_RC20
5.2.0_RC21
5.5.0
5.5.1
5.5.2
5.6.0
5.7.0
5.7.1
5.8.0

6.*

6.0.0
6.0.1
6.0.5
6.0.6
6.0.7

Database specific

{
    "last_known_affected_version_range": "<= 6.0.7"
}