Lucene search

K
wpvulndbFelipe Restrepo RodriguezWPVDB-ID:17287D8A-BA27-42DC-9370-A931EF404995
HistoryJul 15, 2021 - 12:00 a.m.

Form Maker < 1.13.60 - Authenticated Stored XSS

2021-07-1500:00:00
Felipe Restrepo Rodriguez
wpscan.com
16
authenticated stored xss
admin dashboard
attribute escapement
cross-site scripting
security issue
form maker

EPSS

0.001

Percentile

24.8%

The plugin does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PoC

Create or edit a form and add the following payload in the Form Title field "autofocus onmouseover=alert(/XSS/)// save it and move the mouse over the Title field Edit (WPScanTeam): better payload (no interaction needed other than editing the affected Form): " style=“animation-name:rotation” onanimationstart="alert(/XSS/)//

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:17287D8A-BA27-42DC-9370-A931EF404995