Lucene search

K
wpvulndbNGO VAN TUWPVDB-ID:82A81721-0435-45A6-BD5B-DC90186CF803
HistoryMay 25, 2023 - 12:00 a.m.

AI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting

2023-05-2500:00:00
NGO VAN TU
wpscan.com
6
chatbot keywords
admin+ privilege
stored xss
language settings.

0.001 Low

EPSS

Percentile

21.5%

The plugin does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot

PoC

1. Go to “Settings > Language Settings > ChatBot Keywords” 2. Enter the PoC: POC"&gt; in the “Welcome to Help Section”, “Type and Hit Enter”, or “clear our chat history” fields. 3. Save and see the XSS

CPENameOperatorVersion
chatbotlt4.5.6

0.001 Low

EPSS

Percentile

21.5%

Related for WPVDB-ID:82A81721-0435-45A6-BD5B-DC90186CF803