mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-30 02:00:45 +00:00
1013 B
1013 B
CVE-2022-3415
Description
The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message
POC
Reference
- https://wpscan.com/vulnerability/012c5b64-ef76-4539-afd8-40f6c329ae88
- https://wpscan.com/vulnerability/012c5b64-ef76-4539-afd8-40f6c329ae88
Github
No PoCs found on GitHub currently.