WordPress 插件 JetAppointment 在 2.5.2.1 及更早版本中存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于对 'friendlyTime' 参数的输入过滤和输出转义处理不足,导致未经身份验证的攻击者可以在页面中注入任意 Web 脚本。当其他用户访问被注入的页面时,这些脚本将自动执行。注入的恶意载荷会通过未经验证端点 jet_engine_form_booking_submit 存储到数据库表 wp_jet_appointments_
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Crocoblock | JetAppointment | ≤ 2.5.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Crocoblock | JetAppointment | 0 ~ 2.5.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet