当前位置:网站首页>WordPress preview email for wocomerce 1.6.8 cross site scripting
WordPress preview email for wocomerce 1.6.8 cross site scripting
2022-06-23 22:13:00 【Khan security team】
describe : Reflect cross site scripts
Affected plugins :WooCommerce Preview email for
plug-in unit Slug:woo-preview-emails
The affected version :<= 1.6.8
CVE ID:CVE-2021-42363
WooCommerce Preview email is a simple plug-in , Designed to allow site owners to preview through WooCommerce E-mails sent to customers . Unfortunately , The plug-in has a flaw , It makes it possible for an attacker to maliciously Web Script injection “digthis-woocommerce-preview-emails” page .
As part of the plug-in functionality , There is a function to search for orders and generate email previews based on specific orders , So that the administrator or store manager can accurately view the content of the sent email seen by a specific user . Unfortunately , For searching search_orders Parameters are reflected on the page , And no input cleanup or output escape , This allows users to provide arbitrary scripts , When using a payload to access a page , These scripts will be executed in the browser in search_orders Parameter .
It means , If the attacker can successfully persuade the site administrator to click the link , They can make malice JavaScript Execute... In the administrator's browser . This script can be crafted to inject new administrative users , Even modify plug-ins or theme files to include backdoors , This allows an attacker to take full control of the site .
边栏推荐
- Bluetooth chip | Renesas and Ti launch new Bluetooth chip, try Lenz st17h65 Bluetooth ble5.2 chip
- Second kill design of 100 million level traffic architecture
- How the API gateway obtains the URI path and how the API handles local access failure
- What is API gateway link tracking? What is the function of the line monitoring tool?
- Detailed explanation of lkadoc interface tool
- Intel openvino tool suite advanced course & experiment operation record and learning summary
- Error running PyUIC: Cannot start process, the working directory ‘-m PyQt5. uic. pyuic register. ui -o
- TDD development mode recommendation process
- Freiburg University, Hildesheim University and other universities in Germany jointly | zero shot automl with pre trained models (zero sample automl based on pre training model)
- How to control the quality of omics research—— Mosein
猜你喜欢

北大、加州伯克利大學等聯合| Domain-Adaptive Text Classification with Structured Knowledge from Unlabeled Data(基於未標記數據的結構化知識的領域自適應文本分類)

Acl2022 | MVR: multi view document representation for open domain retrieval

Experiment 5 module, package and Library

高阶柱状图之极环图与极扇图

CAD图在线Web测量工具代码实现(测量距离、面积、角度等)
Performance optimization of database 5- database, table and data migration

CAD图在线Web测量工具代码实现(测量距离、面积、角度等)

Error running PyUIC: Cannot start process, the working directory ‘-m PyQt5. uic. pyuic register. ui -o

Teacher lihongyi from National Taiwan University - grade Descent 2

Installation and use of Minio
随机推荐
Digital transformation solution for supply chain platform of mechanical equipment industry
Use bcryptjs to encrypt the password
Improve efficiency, take you to batch generate 100 ID photos with QR code
Kubernetes cluster lossless upgrade practice
Deep understanding of leakcanary
The "Star" industry in the small town is escorted by wechat cloud hosting
How to control the quality of omics research—— Mosein
Teach you how to write a delay queue
Start optimization - directed acyclic graph
Leetcode algorithm interview sprint sorting algorithm theory (32)
Knowda: all in one knowledge mixture model for data augmentation in feed shot NLP
Tencent cloud database tdsql elite challenge Q & A (real-time update)
What is zero copy?
Ten thousand words! Understand the inheritedwidget local refresh mechanism
Some opinions on microservices
[same origin policy - cross domain issues]
The latest research progress of domain generalization from CVPR 2022
2021-12-19: find the missing numbers in all arrays. Give you an n
Second kill design of 100 million level traffic architecture
MySQL architecture SQL foundation 2