Lucene search

K
wpvulndbNhatnamWPVDB-ID:2E38B1BB-4410-45E3-87CA-D47A2CCE9E22
HistoryJul 14, 2022 - 12:00 a.m.

Slide Anything < 2.3.47 - Author+ Cross Site Scripting in slide title

2022-07-1400:00:00
nhatnam
wpscan.com
15
vulnerable plugin
cross site scripting
incomplete fix
javascript payload
admin pages
user roles

EPSS

0

Percentile

14.0%

The plugin does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled. An incomplete fix was introduced in version 2.3.46

PoC

Create new Slide where the tile is the XSS payload: ‘;alert(title);//’ The script then will be executed everywhere when the code is embedded.

EPSS

0

Percentile

14.0%

Related for WPVDB-ID:2E38B1BB-4410-45E3-87CA-D47A2CCE9E22