mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-30 18:20:53 +00:00
20 lines
880 B
Markdown
20 lines
880 B
Markdown
### [CVE-2023-2579](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2579)
|
|

|
|

|
|
&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/daniloalbuqrque/poc-cve-xss-inventory-press-plugin
|
|
- https://wpscan.com/vulnerability/3cfcb8cc-9c4f-409c-934f-9f3f043de6fe
|
|
|
|
#### Github
|
|
- https://github.com/0xn4d/poc-cve-xss-inventory-press-plugin
|
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
|
|