Skip to content

Latest commit

 

History

History
27 lines (16 loc) · 1.04 KB

easy-custom-auto-excerpt.md

File metadata and controls

27 lines (16 loc) · 1.04 KB

Well ,sir ,I just found a Stored-XSS bug here.

ADLab of Venustech

The report link to the wordpress-form is missing, because the manager do not wish to put the public in danger ,I'll just write some details here.

When I login into the wordpress panel, assume I have a low privilege role like a editor user.

Because the admin user has turned on the option of the wp-plugin Easy Custom Auto Excerpt, a normal user like me can also use it.

When I edit the setting page of Excerpt, I write something evil into it:

http://192.168.1.109/wordpress/wp-admin/admin.php?page=tonjoo_excerpt

Weak post para:

tonjoo_ecae_options%5Bcustom_css%5D='"><img src=x onerror=console.log(/xss/)><'"

image

Once the other users or the manager view the page , I'll get the cookies of theirs , or do something more evilly.

image