Lucene search

K
wpvulndbZhongFu Su(JrXnm) of WuHan University WPVDB-ID:66789B32-049E-4440-8B19-658649851010
HistoryJun 27, 2022 - 12:00 a.m.

Download Manager < 3.2.44 - Reflected Cross-Site Scripting

2022-06-2700:00:00
ZhongFu Su(JrXnm) of WuHan University
wpscan.com
13
download manager
plugin
reflected cross-site scripting
url
attribute
history dashboard

EPSS

0.001

Percentile

40.2%

The plugin does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

PoC

https://example.com/wp-admin/edit.php?post_type=wpdmpro&amp;page;=wpdm-stats&amp;type;=history&amp;user;_ids[]=1&">

EPSS

0.001

Percentile

40.2%

Related for WPVDB-ID:66789B32-049E-4440-8B19-658649851010