WordPress Download Manager 3.2.43 Cross Site Scripting ≈ Packet Storm

WordPress Download Manager 3.2.43 Cross Site Scripting ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

WordPress Download Manager 3.2.43 Cross Site Scripting[6]
Authored by Andrea Bocchetti[7]

WordPress Download Manager plugin versions 3.2.43 and below suffer from a cross site scripting vulnerability.

advisories | CVE-2022-2101[8]
SHA-256 | c5e010f3009e39b7db11c52ad43c84317ef6588fbfb45a6713c6d0812c0cf403

Change Mirror[12] Download[13]

        Exploit Title: Download Manager Cross-Site Scripting
Date: 2022-06-16
Exploit Author : Andrea Bocchetti
Vendor Homepage : https://wordpress.org/plugins/download-manager/
Version : <= 3.2.43
Tested on: windows
CVE : CVE-2022-2101
######## Description ########
# 1-) Login in the plugin page
# 2-) add the xss payload in the field "Insert URL"
# 3-) Click on the link , the JS code will be interpreted.

Login[14] or Register[15] to add favorites

File Archive:

June 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec[118]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"