当前位置:网站首页>WordPress plugin wpschoolpress 2.1.16 -'multiple'cross site scripting (XSS)
WordPress plugin wpschoolpress 2.1.16 -'multiple'cross site scripting (XSS)
2022-06-23 22:13:00 【Khan security team】
supply Business Homepage :https://wpschoolpress.com/
Software link :https://wpschoolpress.com/free-download/
edition : The highest 2.1.17( Not included )
test :Ubuntu 20.04 over WordPress 5.8 and apache2
CVE:CVE-2021-24664
The plug-in uses the name sanitize_text_field() Of wordpress Built in functions clean up some fields , But they were not correctly escaped before the attributes were output , Cause storage cross site scripting problems . function wp_sanitize_text_field() escape < and > But no escape image " Such characters , Allow attackers to destroy HTML Enter the tag and inject any javascript.
Proof of concept :
As Administrator
- Add new teacher attendance (/wp-admin/admin.php?page=sch-teacherattendance), Check the absence box and put the following payloads into the reason :“style=animation-name:rotation onanimationstart=alert(/XSS /)// By clicking “ add to ” Button to add other teachers' attendance will trigger XSS - Add a new student attendance (/wp-admin/admin.php?page=sch-attendance), Check the absence box and put the following payloads into the reason :" style=animation-name:rotation onanimationstart=alert(/XSS /)// By clicking “ add to / to update ” Button to add another attendance will trigger XSS
- Add a new topic tag field (/wp-admin/admin.php?page=sch-settings&sc=subField) And put the following payload into “ Field ”:“ autofocus onfocus=alert(/XSS/)// When you edit the created theme tag, it will trigger XSS( namely /admin.php?page=sch-settings&sc=subField&ac=edit&sid=3)
- Create a new theme (/wp-admin/admin.php?page=sch-subject), Include the following payload in the topic name field :“ autofocus onfocus=alert(/XSS/)// When you edit a topic XSS
- Create a new exam using the following payload in the exam name field (/wp-admin/admin.php?page=sch-exams):“ autofocus onfocus=alert(/XSS/)// edit Exam=20 Will trigger XSS
Please note that , Some of them XSS Questions can be asked by teachers ( Moderately privileged user ) perform , But because of wordpress Use HTTPonly cookie, So it is impossible to steal cookie.
边栏推荐
- TDD development mode recommendation process
- Take you to understand the lazy loading of pictures
- Polar cycle graph and polar fan graph of high order histogram
- How do I install the API gateway? What should I pay attention to?
- Tencent cloud server ubuntu18 installs MySQL and logs in remotely
- How the API gateway obtains the URI path and how the API handles local access failure
- Don't let your server run naked -- security configuration after purchasing a new server (Basics)
- The latest research progress of domain generalization from CVPR 2022
- Code implementation of CAD drawing online web measurement tool (measuring distance, area, angle, etc.)
- Raid card with hardware knowledge (5)
猜你喜欢

ICML2022 | 基于对比学习的离线元强化学习的鲁棒任务表示

Freshman girls' nonsense programming is popular! Those who understand programming are tied with Q after reading

Configuring error sets using MySQL for Ubuntu 20.04.4 LTS

Code implementation of CAD drawing online web measurement tool (measuring distance, area, angle, etc.)

Intel openvino tool suite advanced course & experiment operation record and learning summary

The latest research progress of domain generalization from CVPR 2022

使用 Provider 改造屎一样的代码,代码量降低了2/3!

Cloud native practice of meituan cluster scheduling system

Code implementation of CAD drawing online web measurement tool (measuring distance, area, angle, etc.)

Sending network request in wechat applet
随机推荐
Polar cycle graph and polar fan graph of high order histogram
TDD development mode recommendation process
Raid card with hardware knowledge (5)
How to dynamically insert a picture into a QR code
How to use the serial port assistant in STC ISP?
How ppt creates a visual chart
HR SaaS is finally on the rise
How does the API gateway intercept requests? How does the security of the API gateway reflect?
How to build an API gateway and how to maintain an API gateway?
Redis source code analysis -- QuickList of redis list implementation principle
Experiment 5 module, package and Library
The "Star" industry in the small town is escorted by wechat cloud hosting
ACL2022 | MVR:面向开放域检索的多视角文档表征
How to do API gateway routing? What are the other functions of API gateway?
Redis encapsulation instance
Flink practical tutorial: advanced 4-window top n
[同源策略 - 跨域问题]
Second kill design of 100 million level traffic architecture
Analysis of Alibaba cloud Tianchi competition -- prediction of o2o coupon
Using h5ai to build Download Station