Lucene search

K
wpvulndbGabriel3476WPVDB-ID:48DCCF4C-07E0-4877-867D-F8F43AEB5705
HistoryApr 21, 2022 - 12:00 a.m.

VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting

2022-04-2100:00:00
gabriel3476
wpscan.com
6
vikbooking
cross-site scripting
stored
admin
privilege users
xss
settings
email
plugin

EPSS

0.001

Percentile

24.8%

The plugin does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PoC

v < 1.5.7 Add/edit a custom field (/wp-admin/admin.php?option=com_vikbooking&task;=customf) and put the following payload in the Field Name or Popup Link fields: "autofocus/onfocus=alert(/XSS/)// The XSS will be triggered when editing the Custom Field again v < 1.5.8 Add the following payload in the Admin Email settings (at /wp-admin/admin.php?option=com_vikbooking&task;=config): "autofocus/onfocus=alert(/XSS/)// Other settings were also affected

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:48DCCF4C-07E0-4877-867D-F8F43AEB5705