cve/2022/CVE-2022-0402.md
2024-06-18 02:51:15 +02:00

1.1 KiB

CVE-2022-0402

Description

The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting. The action is also lacking CSRF, making the attack easier to perform against any user.

POC

Reference

Github

No PoCs found on GitHub currently.