Lucene search

K
wpvulndbGerard ArallWPVDB-ID:19C1F9C0-E30E-4A9C-8A0C-FBE3384D734A
HistoryApr 01, 2016 - 12:00 a.m.

Cerber Limit Login Attempts <= 2.0.1.6 - Unauthenticated Stored XSS

2016-04-0100:00:00
Gerard Arall
wpscan.com
13

EPSS

0.001

Percentile

40.7%

If the option β€œI’m behind a proxy” is enabled, the visitor IP is read from X-Forwarded-For header, stored & printed in the admin panel without any sanitization / validation.

PoC

Set the X-Forwarded-For header to , and perform an incorrect login.

EPSS

0.001

Percentile

40.7%

Related for WPVDB-ID:19C1F9C0-E30E-4A9C-8A0C-FBE3384D734A