Lucene search

K
wpvulndbKrzysztof ZającWPVDB-ID:60067B8B-9FA5-40D1-817A-929779947891
HistoryJan 31, 2022 - 12:00 a.m.

Crazy Bone <= 0.6.0 - Unauthenticated Stored XSS

2022-01-3100:00:00
Krzysztof Zając
wpscan.com
14
crazy bone plugin
stored xss
login dashboard
unauthenticated
user section

EPSS

0.001

Percentile

44.3%

The plugin does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

PoC

curl ‘https://example.com/wp-login.php’ --data-raw ‘log=a&pwd;=x&wp-submit;=Log+In’ The XSS will be trigged in the ‘All User’ section of the Login Log: https://example.com/wp-admin/users.php?page=crazy-bone%2Fplugin.php&amp;user;_id=-1&amp;status;

EPSS

0.001

Percentile

44.3%

Related for WPVDB-ID:60067B8B-9FA5-40D1-817A-929779947891