WordPress Twenty Fifteen 4.2.1 Cross Site Scripting

2015.05.08
Credit: Omar Kurt
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

Information -------------------- Advisory by Netsparker. Name: DOM XSS Vulnerability in Twenty Fifteen WordPress Theme Affected Software : WordPress Affected Versions: 4.2.1 and probably below Vendor Homepage : https://wordpress.org/ and https://wordpress.org/themes/twentyfifteen/ Vulnerability Type : DOM based Cross-site Scripting Severity : Important CVE-ID: CVE-2015-3429 Netsparker Advisory Reference : NS-15-007 Description -------------------- By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged in user?s session. This means that the malicious hacker can change the logged in user?s password and invalidate the session of the victim while the hacker maintains access. As seen from the XSS example in this article, if a web application is vulnerable to cross-site scripting and the administrator?s session is hijacked, the malicious hacker exploiting the vulnerability will have full admin privileges on that web application. Technical Details -------------------- Proof of Concept URL for DOM XSS in WordPress: http://example.com/wordpress/wp-content/themes/twentyfifteen/genericons/example.html#<img/src/onerror=alert(123)> For more information on DOM based cross-site scripting vulnerabilities read the following article: https://www.netsparker.com/blog/web-security/dom-based-cross-site-scripting-vulnerability/ Advisory Timeline -------------------- 22/04/2015 - First Contact 07/05/2015 - Vulnerability fixed 07/05/2014 - Advisory released Solution -------------------- Download WordPress version 4.2.2 which includes fix for this vulnerability. Credits & Authors -------------------- These issues have been discovered by Omar Kurt while testing Netsparker Web Application Security Scanner - https://www.netsparker.com/web-vulnerability-scanner/ About Netsparker -------------------- Netsparker finds and reports security issues and vulnerabilities such as SQL Injection and Cross-site Scripting (XSS) in all websites and web applications regardless of the platform and the technology they are built on. Netsparker's unique detection and exploitation techniques allows it to be dead accurate in reporting hence it's the first and the only False Positive Free web application security scanner. For more information visit our website on https://www.netsparker.com

References:

https://www.netsparker.com/blog/web-security/dom-based-cross-site-scripting-vulnerability/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top