WordPress 的 "The Contact Form by Supsystic" 插件存在存储型跨站脚本攻击(Stored XSS)漏洞。 漏洞描述: 该插件在 1.10.2 及之前所有版本中,由于对输入数据缺乏足够的过滤和输出时未进行转义,使得未认证的远程攻击者能够向页面的 IP 地址请求头(如 )中注入恶意脚本。当用户访问被注入的页面时,这些脚本将会被执行。 攻击流程: 1. 未认证的 attacker 可以先调用 操作——由于该操作未包含在插件的权限列表中,因此无需身份验证即可访问——以获取一个有效的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| supsysticcom | Contact Form by Supsystic | 0 ~ 1.10.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet