Vulnerabilities > CVE-2022-1216 - Unspecified vulnerability in Advanced Image Sitemap Project Advanced Image Sitemap

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
advanced-image-sitemap-project

Summary

The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.

Vulnerable Configurations

Part Description Count
Application
Advanced_Image_Sitemap_Project
1