WordPress 插件 JetFormBuilder — Dynamic Blocks Form Builder 存在反射型跨站脚本(XSS)漏洞,该漏洞可通过 URL 查询变量参数 触发,具体利用方式为在“计算字段”(Calculated Field)中嵌入恶意脚本。在所有 3.6.5.3 及更早版本中,由于对输入数据缺乏足够的 sanitization(清理)和输出时缺少正确的 escaping(转义),攻击者无需认证即可在页面中注入任意 Web 脚本。若攻击者成功诱导用户执行某些操作(例如点击包含恶意参数的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | 0 ~ 3.6.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet