10Web 开发的 Form Maker – Mobile-Friendly Drag & Drop Contact Form Builder(适用于 WordPress 的移动友好型拖放式联系表单构建器插件)存在反射型跨站脚本(Reflected Cross-Site Scripting)漏洞。该漏洞影响所有版本,包括 1.15.46 及之前版本,原因是输入验证不足且输出未进行转义。这使得未认证的攻击者能够通过诱导用户执行特定操作(如点击链接)而成功将任意网页脚本注入到执行该操作的页面中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | 0 ~ 1.15.46 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet