WordPress 的 wpForo 论坛插件存在存储型跨站脚本攻击(Stored Cross-Site Scripting, XSS)漏洞。该漏洞出现在版本 3.1.6 及更早版本中,具体位于“telegram”个人简介字段。 漏洞成因在于:在 操作中,对输入数据的清理和输出时的转义处理不足。具体而言,原始的 数组被直接复制到 变量中,而后续的 和 函数仅对另一个平行的 引用进行操作。这导致 未经验证和清理便通过 持久化存储。 在前端渲染时, 函数会对实体编码进行反转,而 函数在输出该值时未进行适当的转义处理。因
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tomdever | wpForo Forum | 0 ~ 3.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet