Lucene search

K
wpvulndbJrXnmWPVDB-ID:BECA7AFD-8F03-4909-BEA0-77B63513564B
HistoryNov 22, 2021 - 12:00 a.m.

Icegram < 2.0.5 - Reflected Cross-Site Scripting

2021-11-2200:00:00
JrXnm
wpscan.com
9

0.001 Low

EPSS

Percentile

40.2%

The plugin does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

PoC

The XSS will be triggered when moving the mouse over the text in the response

CPENameOperatorVersion
icegramlt2.0.5

0.001 Low

EPSS

Percentile

40.2%

Related for WPVDB-ID:BECA7AFD-8F03-4909-BEA0-77B63513564B