mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 09:12:08 +00:00
801 B
801 B
CVE-2017-17043
Description
The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly.
POC
Reference
- https://packetstormsecurity.com/files/145060/wpemagmc10-xss.txt
- https://wpvulndb.com/vulnerabilities/8964