WordPress 的 The Dear Flipbook 插件(PDF 翻页书、3D 翻页书、PDF 嵌入、PDF 查看器)在所有版本中(包括 2.4.30 及以下版本)存在存储型跨站脚本(Stored XSS)漏洞。该漏洞由输入净化不足和输出转义缺失导致,受影响参数为“post_content(.dvcss 元素的 class 属性)”。 这意味着拥有贡献者(contributor)或更高权限的已认证攻击者,可以注入任意 Web 脚本到页面中;当用户访问被注入的页面时,这些脚本将会执行。攻击载荷以 Base64
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dearhive | DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer | 0 ~ 2.4.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet