Lucene search

K
wpvulndbWpvulndbWPVDB-ID:EA806115-14AB-4BC4-A272-2141CB14454A
HistoryApr 12, 2023 - 12:00 a.m.

ChatBot < 4.5.1 - Admin+ Stored XSS

2023-04-1200:00:00
wpscan.com
3
chatbot plugin
stored xss
admin privilege
unfiltered_html
sanitization
multisite
poc
security vulnerability

0.001 Low

EPSS

Percentile

23.5%

The plugin does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PoC

Put the following payload in the Your Company or Website Name settings of the plugin and save: " style=animation-name:rotation onanimationstart=alert(/XSS/)// All settings are affected

CPENameOperatorVersion
chatbotlt4.4.7

0.001 Low

EPSS

Percentile

23.5%

Related for WPVDB-ID:EA806115-14AB-4BC4-A272-2141CB14454A