Lucene search

K
wpvulndbKishore HariramWPVDB-ID:372A66CA-1C3C-4429-86A5-81DBDAA9EC7D
HistoryMay 05, 2021 - 12:00 a.m.

Hana Flv Player <= 3.1.3 - Authenticated Stored Cross-Site Scripting (XSS)

2021-05-0500:00:00
Kishore Hariram
wpscan.com
8

0.001 Low

EPSS

Percentile

25.0%

The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the “Default Skin” field.

PoC

Step1: Install and activate the plugin. Step2: Go to the plugin setting. Step3: Enter the following payload in the field “Default Skin” xss">
<input type=‘text’ name=“hflv_skin” value="xss Step4: Now the script is stored and whenever the user goes to the plugin the script will be executed. </p>

CPENameOperatorVersion
hana-flv-playereq*

0.001 Low

EPSS

Percentile

25.0%

Related for WPVDB-ID:372A66CA-1C3C-4429-86A5-81DBDAA9EC7D