Lucene search

K
wpexploitMuhamad hidayatWPEX-ID:598D5C1B-7930-46A6-9A31-5E08A5F14907
HistoryMar 28, 2022 - 12:00 a.m.

Easy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting

2022-03-2800:00:00
muhamad hidayat
101
easy digital downloads
cross-site scripting
admin
security vulnerability
xss
unauthenticated
frontend
exploit
reports page

EPSS

0.001

Percentile

21.4%

The plugin does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

Create/edit a Download and put the following payload in the File Name field: <img src=x:x onerror=alert(/XSS/)>
Download the file via the frontend (as unauthenticated for example)
The XSS will be triggered when viewing the Reports > Logs Page (/wp-admin/edit.php?post_type=download&page=edd-reports&tab=logs)

EPSS

0.001

Percentile

21.4%

Related for WPEX-ID:598D5C1B-7930-46A6-9A31-5E08A5F14907