{"api_version":"1","generated_at":"2026-07-23T13:16:14+00:00","cve":"CVE-2022-0385","urls":{"html":"https://cve.report/CVE-2022-0385","api":"https://cve.report/api/cve/CVE-2022-0385.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-0385","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-0385"},"summary":{"title":"CVE-2022-0385","description":"The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2022-02-28 09:15:00","updated_at":"2022-03-08 16:52:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/60067b8b-9fa5-40d1-817a-929779947891","name":"https://wpscan.com/vulnerability/60067b8b-9fa5-40d1-817a-929779947891","refsource":"MISC","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-0385","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0385","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Krzysztof Zając","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"385","vulnerable":"1","versionEndIncluding":"0.6.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"crazy_bone_project","cpe5":"crazy_bone","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2022-0385","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"Crazy Bone <= 0.6.0 - Unauthenticated Stored XSS"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Crazy Bone","version":{"version_data":[{"version_affected":"<=","version_name":"0.6.0","version_value":"0.6.0"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting"}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://wpscan.com/vulnerability/60067b8b-9fa5-40d1-817a-929779947891","name":"https://wpscan.com/vulnerability/60067b8b-9fa5-40d1-817a-929779947891"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-79 Cross-site Scripting (XSS)","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Krzysztof Zając"}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-02-28 09:15:00","lastModifiedDate":"2022-03-08 16:52:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:crazy_bone_project:crazy_bone:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"0.6.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"385","Ordinal":"227108","Title":"CVE-2022-0385","CVE":"CVE-2022-0385","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"385","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}