WordPress 插件 “Awesome Support – WordPress HelpDesk & Support Plugin”(版本 6.4.0 及之前所有版本)存在存储型跨站脚本攻击(Stored XSS)漏洞,原因是其对 参数的输入净化不足且输出未进行转义。该漏洞允许拥有订阅者(Subscriber)级别或更高权限的已认证攻击者在页面中注入任意 Web 脚本,当其他用户访问被注入的页面时,这些脚本将被执行。 该漏洞可被订阅者级别的用户利用来攻击其他账户,原因在于:AJAX 处理程序接受任意的 ID,但
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | ≤ 6.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | 0 ~ 6.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet