Advertisement






WordPress Concours 1.1 Cross Site Scripting

CVE Category Price Severity
CVE-2017-17719 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2017-12-20
CPE
cpe:cpe:/a:wordpress:concours:1.1
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017120150

Below is a copy:

WordPress Concours 1.1 Cross Site Scripting
Product: WordPress Concours Plugin - https://wordpress.org/plugins/wp-concours/
Vendor: Olyos
Tested version: 1.1
CVE ID: CVE-2017-17719

** CVE description **
A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.

** Technical details **
In wp-concours/includes/concours_page.php:18, $_REQUEST['result_message'] is stored in the $message_str variable without proper sanitization. This variable is then echoed back to user on line 28.

Vulnerable code:
https://plugins.trac.wordpress.org/browser/wp-concours/trunk/includes/concours_page.php#L18

** Proof of Concept **
http://<host>/wordpress/wp-admin/admin.php?page=concours&result_message=<script>alert(document.cookie);</script>

** Solution **
No fix available yet.

** Timeline **
28/09/2017: vendor contacted; vendor asks for technical report
06/10/2017: requested an update regarding the fix; vendor says in November
05/12/2017: sent an e-mail to warn about the release of that advisory; no reply
19/12/2017: report published

** Credits **
Vulnerability discovered by Nicolas Buzy-Debat working at Orange Cyberdefense Singapore (CERT-LEXSI).

--
Best Regards,

Nicolas Buzy-Debat
Orange Cyberdefense Singapore (CERT-LEXSI)

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum