Lucene search

K
wpvulndbAkash Rajendra PatilWPVDB-ID:D60634A3-CA39-43BE-893B-FF9BA625360F
HistoryJul 19, 2021 - 12:00 a.m.

My Site Audit <= 1.2.4 - Authenticated Stored Cross-Site Scripting (XSS)

2021-07-1900:00:00
Akash Rajendra Patil
wpscan.com
8
site audit
plugin vulnerability
authenticated stored cross-site scripting

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PoC

Create an audit with the following payload in the Audit Name field: "> Then view the ‘All Audit’ or ‘Dashboard’ (of the plugin) pages to trigger the XSS

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:D60634A3-CA39-43BE-893B-FF9BA625360F