WordPress LearnPress 插件(版本 ≤ 4.4.9.1)存在一个存储型跨站脚本(Stored XSS)漏洞,允许已认证的教师通过测验题目的“提示”和“说明”字段注入恶意脚本。拥有“教师(Instructor)”角色的攻击者可通过 update_question AJAX 处理器提交未经过滤的恶意负载,这些脚本将在每个参与该测验的学生会话中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ThimPress | LearnPress | 0 ~ 4.4.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet