关键信息 EDB-ID: 45305 CVE: N/A Author: Renos Nikolaou Type: WEBAPPS Platform: PHP Date: 2018-08-30 Vulnerable App: WordPress Plugin Jibu Pro 1.7 漏洞描述 Title: WordPress Plugin Jibu Pro 1.7 - Cross-Site Scripting Description: Jibu Pro is prone to Stored Cross Site Scripting vulnerabilities because it fails to properly sanitize user-supplied input. 漏洞利用步骤 1. Login as a user who have access to Jibu Pro plugin. 2. Jibu-Pro --> Create Quiz. 3. At the Quiz Name type: poc">alert(1), then fill the remaining fields and click Save. 4. Click Create New Questions, fill the fields and click Save. 5. Copy the Shortcode [Test Number] into any post or page and visit it via browser. Tags Cross-Site Scripting (XSS) 关键字段 Google Dork: inurl:"/wp-content/plugins/jibu-pro" Software Link: https://downloads.wordpress.org/plugin/jibu-pro.1.7.zip Tested on: Kali Linux