当前位置:网站首页>WordPress preview email for wocomerce 1.6.8 cross site scripting
WordPress preview email for wocomerce 1.6.8 cross site scripting
2022-06-23 22:13:00 【Khan security team】
describe : Reflect cross site scripts
Affected plugins :WooCommerce Preview email for
plug-in unit Slug:woo-preview-emails
The affected version :<= 1.6.8
CVE ID:CVE-2021-42363
WooCommerce Preview email is a simple plug-in , Designed to allow site owners to preview through WooCommerce E-mails sent to customers . Unfortunately , The plug-in has a flaw , It makes it possible for an attacker to maliciously Web Script injection “digthis-woocommerce-preview-emails” page .
As part of the plug-in functionality , There is a function to search for orders and generate email previews based on specific orders , So that the administrator or store manager can accurately view the content of the sent email seen by a specific user . Unfortunately , For searching search_orders Parameters are reflected on the page , And no input cleanup or output escape , This allows users to provide arbitrary scripts , When using a payload to access a page , These scripts will be executed in the browser in search_orders Parameter .
It means , If the attacker can successfully persuade the site administrator to click the link , They can make malice JavaScript Execute... In the administrator's browser . This script can be crafted to inject new administrative users , Even modify plug-ins or theme files to include backdoors , This allows an attacker to take full control of the site .
边栏推荐
- Tdsql elite challenge CVM voucher usage guide
- Apt attack
- To develop AI face comparison, how to output multiple faces with comparative similarity?
- How to use the serial port assistant in STC ISP?
- Learn about reentrantlock
- HR SaaS is finally on the rise
- Notepad++ installing the jsonview plug-in
- Environment construction of go language foundation
- BenchCLAMP:评估语义分析语言模型的基准
- New high-speed random graph API interface, the first sci-fi graph API interface
猜你喜欢

微信小程序中发送网络请求

北大、加州伯克利大学等联合| Domain-Adaptive Text Classification with Structured Knowledge from Unlabeled Data(基于未标记数据的结构化知识的领域自适应文本分类)

Bluetooth chip | Renesas and Ti launch new Bluetooth chip, try Lenz st17h65 Bluetooth ble5.2 chip

Peking University, University of California Berkeley and others jointly | domain adaptive text classification with structured knowledge from unlabeled data (Domain Adaptive Text Classification Based o

Experiment 5 module, package and Library

Cloud native practice of meituan cluster scheduling system

Freshman girls' nonsense programming is popular! Those who understand programming are tied with Q after reading

从CVPR 2022看域泛化(Domain Generalization)最新研究进展

HDLBits-&gt;Circuits-&gt;Arithmetic Circuitd-&gt;3-bit binary adder

CAD图在线Web测量工具代码实现(测量距离、面积、角度等)
随机推荐
How does the fortress remote login server operate? What is the application value of Fortress machine?
Code implementation of CAD drawing online web measurement tool (measuring distance, area, angle, etc.)
Using barcode software to make certificates
A batch layout WAF script for extraordinary dishes
To develop AI face comparison, how to output multiple faces with comparative similarity?
Sending network request in wechat applet
MySQL architecture SQL foundation 2
2021-12-18: find all letter ectopic words in the string. Given two characters
Teacher lihongyi from National Taiwan University - grade Descent 2
Tencent cloud database tdsql elite challenge Q & A (real-time update)
Bluetooth chip | Renesas and Ti launch new Bluetooth chip, try Lenz st17h65 Bluetooth ble5.2 chip
How to realize batch generation of serial number QR code
HDLBits-&gt; Circuits-&gt; Arithmetic Circuitd-&gt; 3-bit binary adder
[open source]goravel, a fully functional and extensible golang web application framework
How do fortress computers log in to the server? What is the role of the fortress machine?
How to improve the high concurrency of the server
Manually push a message platform
University of North China, Berkeley University of California, etc. | Domain Adaptive Text Classification with structural Knowledge from unlabeled data
TDD development mode recommendation process
Detailed explanation of lkadoc interface tool