WordPress 插件“The Social Chat – Click To Chat App Button”在所有版本(包括 8.6.2 及之前版本)中,由于输入验证和输出转义不足,其 数据框中的 JSON 属性存在存储型跨站脚本(Stored Cross-Site Scripting)漏洞。 这意味着,拥有贡献者(contributor)及以上权限的已认证攻击者,可以通过在页面的数据框中注入任意 Web 脚本,当用户访问该页面时脚本将被执行。利用此漏洞无需用户额外交互:只需在注入的数据框 JSON 中将 和
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quadlayers | Social Chat – Click To Chat App Button | 0 ~ 8.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet