Lucene search

K
wpvulndbBartlomiej MarekWPVDB-ID:9EC03EF0-0C04-4517-B761-DF87AF722A64
HistoryOct 16, 2023 - 12:00 a.m.

URL Shortify < 1.7.9.1 - Admin+ Stored XSS

2023-10-1600:00:00
Bartlomiej Marek
wpscan.com
4
url shortify plugin
stored xss
admin+
cross-site scripting

0.0004 Low

EPSS

Percentile

14.0%

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PoC

Multiple parameters in the plugin’s settings are vulnerable to cross-site scripting. Links -> Edit Link - “Short URL” payload: 9onp" onmouseover=alert(3) abc=" - “Title” payload: KaizenCoders" onmouseover=alert(1) abc=" Groups -> Edit Group - “Name” payload: title" onmouseover=alert(2) abc="

CPENameOperatorVersion
eq1.7.9.1

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:9EC03EF0-0C04-4517-B761-DF87AF722A64