Lucene search

K
wpvulndbGabriel3476WPVDB-ID:19A9E266-DAF6-4CC5-A300-2B5436B6D07D
HistoryApr 21, 2022 - 12:00 a.m.

VikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF

2022-04-2100:00:00
Gabriel3476
wpscan.com
14
vikbooking
hotel booking engine
pms
stored xss
csrf
csrf attack
xss payload
statistics tracking settings

EPSS

0.001

Percentile

26.3%

The plugin does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack

PoC

XSS will be triggered in the Statistics Tracking Settings: https://example.com/wp-admin/admin.php?option=com_vikbooking&amp;task;=trkconfig

EPSS

0.001

Percentile

26.3%

Related for WPVDB-ID:19A9E266-DAF6-4CC5-A300-2B5436B6D07D