CVE-2021-24452: WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting

CVE-2021-24452: WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2021-24452: WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-24452: wordpress W3 Total Cache <2.1.5 – Cross-Site Scripting

漏洞描述

WordPress W3 Total Cache plugin before 2.1.5 is susceptible to cross-site scripting via the extension parameter in the Extensions dashboard, when the setting 'Anonymously track usage to improve product quality' is enabled. The parameter is output in a JavaScript context without proper escaping. This can allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享