当前位置:网站首页>WordPress preview email for wocomerce 1.6.8 cross site scripting
WordPress preview email for wocomerce 1.6.8 cross site scripting
2022-06-23 22:13:00 【Khan security team】
describe : Reflect cross site scripts
Affected plugins :WooCommerce Preview email for
plug-in unit Slug:woo-preview-emails
The affected version :<= 1.6.8
CVE ID:CVE-2021-42363
WooCommerce Preview email is a simple plug-in , Designed to allow site owners to preview through WooCommerce E-mails sent to customers . Unfortunately , The plug-in has a flaw , It makes it possible for an attacker to maliciously Web Script injection “digthis-woocommerce-preview-emails” page .
As part of the plug-in functionality , There is a function to search for orders and generate email previews based on specific orders , So that the administrator or store manager can accurately view the content of the sent email seen by a specific user . Unfortunately , For searching search_orders Parameters are reflected on the page , And no input cleanup or output escape , This allows users to provide arbitrary scripts , When using a payload to access a page , These scripts will be executed in the browser in search_orders Parameter .
It means , If the attacker can successfully persuade the site administrator to click the link , They can make malice JavaScript Execute... In the administrator's browser . This script can be crafted to inject new administrative users , Even modify plug-ins or theme files to include backdoors , This allows an attacker to take full control of the site .
边栏推荐
- Detailed explanation of logical structure, physical structure and data operation
- One article to help you understand automatic injection
- Completely open source and permanently free, this markdown editor is really fragrant!
- Ffmpeg for audio and video commands
- CMU博士论文 | 通过记忆的元强化学习,118页pdf
- [js] generate random array
- Practice of business level disaster recovery switching drill
- Summary of redis Functions PHP version
- [js] 生成随机数组
- Start optimization - directed acyclic graph
猜你喜欢

Peking University, University of California Berkeley and others jointly | domain adaptive text classification with structured knowledge from unlabeled data (Domain Adaptive Text Classification Based o

北大、加州伯克利大学等联合| Domain-Adaptive Text Classification with Structured Knowledge from Unlabeled Data(基于未标记数据的结构化知识的领域自适应文本分类)

HDLBits-&gt;Circuits-&gt;Arithmetic Circuitd-&gt;3-bit binary adder

从CVPR 2022看域泛化(Domain Generalization)最新研究进展

Code implementation of CAD drawing online web measurement tool (measuring distance, area, angle, etc.)

ACL2022 | MVR:面向开放域检索的多视角文档表征

CAD图在线Web测量工具代码实现(测量距离、面积、角度等)

Using the provider to transform the shit like code, the amount of code is reduced by 2/3!

Polar cycle graph and polar fan graph of high order histogram

Installation and use of Minio
随机推荐
Open source C # WPF control library -newbeecoder UI usage guide (I)
WordPress plug-in recommendation
Devops sharing: how to hold the meeting?
How to realize batch generation of serial number QR code
Code implementation of CAD drawing online web measurement tool (measuring distance, area, angle, etc.)
Activiti practice
Detailed explanation of lkadoc interface tool
What causes the applet SSL certificate to expire? How to solve the problem when the applet SSL certificate expires?
Meaning of the last seven digits of wider face
v-chart
How to wrap QR code data
The 10th Blue Bridge Cup single chip microcomputer
Environment construction of go language foundation
How API gateway finds the role of microserver gateway in microservices
HDLBits-&gt; Circuits-&gt; Arithmetic Circuitd-&gt; 3-bit binary adder
How to solve the loss of video source during easynvr split screen switching?
Leetcode algorithm interview sprint sorting algorithm theory (32)
TDD development mode recommendation process
《阿里云天池大赛赛题解析》——O2O优惠卷预测
The most common usage scenarios for redis