WordPress 插件“The Newsletter – Send awesome emails from WordPress”在所有 9.3.8 及更早版本中,由于输入净化不足且未对输出进行转义,存在反射型跨站脚本攻击(Reflected Cross-Site Scripting)漏洞。该漏洞通过 URL 中的 'nn' 参数被触发。未认证的攻击者若能诱导用户点击一个包含恶意脚本的链接,即可在页面中注入任意 Web 脚本,脚本在页面执行。成功利用此漏洞要求受害者为已登录的管理员,因为反爬虫(antibot)检查
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| satollo | Newsletter – Send awesome emails from WordPress | ≤ 9.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| satollo | Newsletter – Send awesome emails from WordPress | 0 ~ 9.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet