Lucene search

K
wpvulndbDaniel RufWPVDB-ID:8C8DAD47-8591-47DC-B84F-8C5CB18B2D78
HistoryJun 01, 2022 - 12:00 a.m.

Clean-Contact <= 1.6 - Arbitrary Settings Update to Stored XSS via CSRF

2022-06-0100:00:00
Daniel Ruf
wpscan.com
8
plugin
csrf
stored xss
vulnerability

EPSS

0.001

Percentile

25.9%

The plugin does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well

PoC

EPSS

0.001

Percentile

25.9%

Related for WPVDB-ID:8C8DAD47-8591-47DC-B84F-8C5CB18B2D78