漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting
Vulnerability Description
The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstructed as raw markup, which wp_kses_post() does not strip because it retains img elements and data-* attributes, and because the public REST endpoint /iawp/search accepts unauthenticated requests as long as they carry a signature that is itself embedded in public page HTML. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
WordPress Independent Analytics – WordPress Analytics Plugin 跨站脚本漏洞
Vulnerability Description
WordPress Independent Analytics – WordPress Analytics Plugin是WordPress基金会的一款网站流量分析插件。 WordPress Independent Analytics – WordPress Analytics Plugin 2.15.0及之前版本存在跨站脚本漏洞,该漏洞源于get_cell_content()函数在esc_url()之后应用urldecode(),导致百分号编码的HTML可绕过URL验证并重构为原始标记,且wp_kses
CVSS Information
N/A
Vulnerability Type
N/A