Lucene search

K
wpvulndbRizacan TufanWPVDB-ID:524928D6-D4E9-4A2F-B410-46958DA549D8
HistorySep 15, 2022 - 12:00 a.m.

TaskBuilder < 1.0.8 - Subscriber+ Stored XSS via SVG file upload

2022-09-1500:00:00
Rizacan Tufan
wpscan.com
7
taskbuilder
plugin
stored xss
svg
file upload
authentication

EPSS

0.001

Percentile

24.8%

The plugin does not validate and sanitise task’s attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file

PoC

Create a SVG with the following content: As any authenticated user, such as subscriber: - Go to http://vuln.local/wp-admin/admin.php?page=wppm-tasks - Choose any tasks (create one if there aren’t any) - Focus on “Write a comment”. - Click on “Attach Files” and select the SVG created above - Click on “Send”. - View the attached SVG by clicking on its URL (https://example.com/?wppm_attachment=86&amp;tid;=1&amp;tac;=OtjI9JpnQU), which will trigger the XSS

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:524928D6-D4E9-4A2F-B410-46958DA549D8