Lucene search

K
wpexploitWpvulndbWPEX-ID:533D3CE1-C31D-4B81-BBC5-1451E5ABD962
HistoryDec 09, 2020 - 12:00 a.m.

DiveBook <= 1.1.4 - Unauthenticated Reflected XSS

2020-12-0900:00:00
wpvulndb
48
divebook
unauthenticated
reflected xss
vulnerability
javascript
browser
attack
exploit
parameters

EPSS

0.001

Percentile

39.5%

:A reflected Cross-Site Scripting vulnerability exists within the DiveBook log’s filter functionality. Arbitrary URL parameters are reflected into the application’s response, rendered by the browser as HTML or JavaScript. An attacker may abuse this functionality by sending a victim a crafted link containing JavaScript, which will execute within the context of the victim’s browser. The “scrolled” parameter is also vulnerable." Note (WPScanTeam): The attack will only work with web browsers not encoding URL parameters

The PoC will be displayed once the issue has been remediated

EPSS

0.001

Percentile

39.5%

Related for WPEX-ID:533D3CE1-C31D-4B81-BBC5-1451E5ABD962