关联漏洞
标题:WordPress 跨站脚本漏洞 (CVE-2022-0234)Description:WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 Wordpress Plugin WOOCS 中存在跨站脚本漏洞,该漏洞源于产品未对woocs_get_products_price_html请求的woocs_in_order_currency参数中的特殊字符进行有效处理。攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响:Wordpress Plugin WOOCS 1.3.7.5 之前
Description
WordPress WOOCS plugin before 1.3.7.5 is susceptible to cross-site scripting. The plugin does not sanitize and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action, available to both unauthenticated and authenticated users, before outputting it back in the response. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
文件快照
id: CVE-2022-0234
info:
name: WordPress WOOCS < 1.3.7.5 - Cross-Site Scripting
author: Akincibo
...
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。