Best Website-BuildersBest Website-Builders
    What's Hot

    OPP officer guilty of sexual assault on unconscious woman and recording it to ‘teach her a lesson’

    March 30, 2023

    Yoghurt maker Muller pays £100K to charity after river discharge

    March 30, 2023

    Billionaire Howard Schultz Annoyed About Being Called a Billionaire

    March 30, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website-BuildersBest Website-Builders
    • Home
    • CSS

      ChatGPT Made Me Cry and Other Adventures in AI Land

      March 29, 2023

      Around Town – Northeast Times

      March 29, 2023

      iOS 16.4: All New Emojis for iPhone

      March 29, 2023

      Citi strengthens ASEAN team with key appointments

      March 29, 2023

      Kingsman Potatoes: Cygnet PB expands commercial trials of this high-yielding, climate-tolerant variety in the US

      March 29, 2023
    • Joomla

      An In-Depth Study of the Market Status, Trends and Top Players of the Open Source Content Management Systems Market

      March 27, 2023

      Save Thousands On Web Hosting With iBrave, Now Only $86

      March 23, 2023

      In Vitro Transcription Services Market Analysis, Research Study with Shanghai Zhishuo Biotechnology Co., Yunzhou Biotechnology Co.

      March 23, 2023

      Current state of UK content management systems

      March 23, 2023

      Reseller Hosting Business: Important Q&A

      March 21, 2023
    • PHP

      Kentucky Bans Gender Affirming Care for Transgender Youth

      March 29, 2023

      The “Mean Girl” host said she doesn’t wash her hands after using the restroom. Doctors say it’s terrible and unsafe.

      March 29, 2023

      Juno Temple and Brett Goldstein explain Roy and Keeley’s ‘heartbreaking’ breakup

      March 29, 2023

      Groom Your Beard Like a Pro: Top Rated Beard Care Products

      March 29, 2023

      FDA Approves Narcan for Over-the-Counter Use

      March 29, 2023
    • UX

      Heylol, Public Messenger App for Young Adults and Teenagers, Announces New Streak Feature

      March 30, 2023

      Netskope and Zoom work together to improve security posture and stay compliant

      March 29, 2023

      8 Key End-User Experience Monitoring Metrics for VDI

      March 29, 2023

      Navy Federal launches new initiative to continue member-focused mission

      March 29, 2023

      Two Latest Products in Q2 Will Help Financial Institutions Personalize User Experiences at Scale

      March 29, 2023
    • Web Builders
      1. Web Design
      2. View All

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      Can Religious Freedom Be Saved? This group is racing the clock to teach America’s first freedom

      February 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023

      Is There A Market For Rap-Themed Slot Games? – Rap Review

      January 19, 2023
    • WordPress

      Calm down, ChatGPT isn’t really artificial intelligence

      March 30, 2023

      Hackers can hijack your Wi-Fi with this worrying security flaw

      March 29, 2023

      This Siri replacement may be the closest thing to using ChatGPT on your iPhone

      March 29, 2023

      Tools like ChatGPT could lead to major unemployment worldwide

      March 29, 2023

      North Korean APT43 hackers target organizations to launder cryptocurrencies using the cloud

      March 29, 2023
    • Realtoz
      • Our Other Sites
    • More News
    Best Website-BuildersBest Website-Builders
    Home » Found a vulnerability in the Gutenberg plugin for WordPress?
    Wordpress

    Found a vulnerability in the Gutenberg plugin for WordPress?

    websitebuildersnowBy websitebuildersnowAugust 2, 2022No Comments5 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The US government’s National Vulnerability Database has published a notice regarding vulnerabilities discovered in the official WordPress Gutenberg plugin. However, according to the person who found it, WordPress is said not to acknowledge that it is a vulnerability.

    Stored Cross-Site Scripting (XSS) Vulnerability

    XSS is a type of vulnerability that occurs when someone can upload something like a form or script that is not normally allowed.

    Most forms and other website inputs are validated for expected updates and filtered out dangerous files.

    An example is a form that uploads an image that cannot block an attacker from uploading a malicious script.

    According to the non-profit Open Web Application Security Project, an organization that helps improve software security, a successful XSS attack can:

    “XSS can be used by attackers to send malicious scripts to unsuspecting users.

    The end user’s browser has no way of knowing that the script should not be trusted and will execute it.

    Malicious scripts can access cookies, session tokens, or other sensitive information held by the browser and used by the site because the script is assumed to be from a trusted source.

    These scripts can even rewrite the content of HTML pages. ”

    Common Vulnerabilities and Exposures – CVE

    An organization named CVE serves as a way of documenting vulnerabilities and disseminating findings to the public.

    Organizations supported by the U.S. Department of Homeland Security investigate vulnerability findings and, if accepted, assign the vulnerability a CVE number that serves as an identification number for that particular vulnerability.

    Gutenberg Vulnerability Discovered

    Security research has uncovered what appears to be a vulnerability. The discovery was submitted to his CVE, the discovery was approved, a CVE ID number was assigned, and the discovery became an official vulnerability.

    The XSS vulnerability has been given the ID number CVE-2022-33994.

    A vulnerability report published on the CVE site contains the following description:

    “The Gutenberg plugin for WordPress up to 13.7.3 allows the ‘Insert from URL’ feature to XSS saved by the Contributor role via an SVG document.

    Note: XSS payloads are not executed in the context of the WordPress instance’s domain. However, similar attempts by a low-privileged user to view his SVG documents have been blocked by some similar products, and this difference in behavior could prove a security risk to some of his WordPress site administrators. It may be related. ”

    This means that someone with contributor-level privileges could inject malicious files into your website.

    The way to do that is to insert an image from a URL.

    Gutenberg offers three ways to upload images.

    1. to upload
    2. Select an existing image from your WordPress media library
    3. Insert image from URL

    According to security researchers, this last method is the source of the vulnerability because it allows images with filenames with arbitrary extensions to be uploaded to WordPress via URLs that are not allowed in the upload feature.

    Is it really a vulnerability?

    Researchers reported this vulnerability to WordPress. However, according to the person who discovered it, WordPress didn’t recognize it as a vulnerability.

    This is what the researcher wrote:

    “We discovered a stored cross-site scripting vulnerability in WordPress, which was dismissed and labeled as beneficial by the WordPress team.

    Today is the 45th day since I reported the vulnerability, and as of this writing, the vulnerability has not yet been patched…”

    So there seems to be a question whether WordPress is right and the US government-backed CVE Foundation is wrong (or vice versa) as to whether this is an XSS vulnerability.

    Researchers claim that this is a real vulnerability and provide CVE approval to verify their claims.

    Additionally, the researcher hints or suggests that allowing the WordPress Gutenberg plugin to upload images via a URL may not be good practice, and other companies may not allow such uploads. I am pointing out that it is not allowed.

    “If so, please tell me why… …companies such as Google and Slack go so far as to validate files loaded via URLs and reject them if they are found to be SVG. was there!

    …Google and Slack… don’t allow SVG files to be loaded via URL, but WordPress does!”

    What should I do?

    WordPress does not appear to consider this vulnerability to be a vulnerability or a problem-causing vulnerability, and has not issued a patch for it.

    The official vulnerability report states that Gutenberg versions up to 13.7.3 contain the vulnerability.

    However, 13.7.3 is the latest version.

    According to the official WordPress Gutenberg changelog, which documents all past changes and also publishes a description of future changes, no fixes have been made or planned for this (alleged) vulnerability.

    So the question is, is there anything to fix?

    Quote

    U.S. Government Vulnerability Database Report on Vulnerability

    CVE-2022-33994 Details

    Report published on official CVE site

    CVE-2022-33994 Details

    Read the researcher’s findings

    CVE-2022-33994:- XSS stored in WordPress


    Featured image from Shutterstock/Kues





    Source link

    Share this:

    • Tweet
    • Email
    • Pocket
    • Mastodon
    • WhatsApp
    • Telegram
    • Share on Tumblr
    • Print
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleNeed to edit email code – HTML & CSS – SitePoint Forums
    Next Article Social network cohost lets users turn posts into games
    websitebuildersnow
    • Website

    Related Posts

    Calm down, ChatGPT isn’t really artificial intelligence

    March 30, 2023

    Hackers can hijack your Wi-Fi with this worrying security flaw

    March 29, 2023

    This Siri replacement may be the closest thing to using ChatGPT on your iPhone

    March 29, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    OPP officer guilty of sexual assault on unconscious woman and recording it to ‘teach her a lesson’

    March 30, 2023

    Yoghurt maker Muller pays £100K to charity after river discharge

    March 30, 2023

    Billionaire Howard Schultz Annoyed About Being Called a Billionaire

    March 30, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.