« Volver al listado

CVE-2022-0642

Estado: ModificadaMedia (5.4)—

El plugin JivoChat Live Chat de WordPress versiones anteriores a 1.3.5.4, no comprueba apropiadamente los tokens de tipo CSRF en las peticiones POST a la página de administración del plugin, y no sanea algunos parámetros, conllevando una vulnerabilidad de tipo Cross-Site Scripting almacenado en la que un atacante puede engañar a un administrador conectado para inyectar javascript arbitrario

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-0642",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "JivoChat Live Chat – WP live chat plugin for WordPress",
          "versions": [
            {
              "status": "affected",
              "version": "1.3.5.4",
              "lessThan": "1.3.5.4",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-30T09:15:08.757",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/099cf9b4-0b3a-43c6-8ca9-7c2d50f86425",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/099cf9b4-0b3a-43c6-8ca9-7c2d50f86425",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "contact@wpscan.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript."
    },
    {
      "lang": "es",
      "value": "El plugin JivoChat Live Chat de WordPress versiones anteriores a 1.3.5.4, no comprueba apropiadamente los tokens de tipo CSRF en las peticiones POST a la página de administración del plugin, y no sanea algunos parámetros, conllevando una vulnerabilidad de tipo Cross-Site Scripting almacenado en la que un atacante puede engañar a un administrador conectado para inyectar javascript arbitrario"
    }
  ],
  "lastModified": "2026-06-17T04:20:59.320",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jivochat:jivochat:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95D50309-404B-424B-B394-B6CD96A604C7",
              "versionEndExcluding": "1.3.5.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}