vendor:
Ultimate Product Catalogue
by:
Felipe Molina de la Torre
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF) & Cross-Site Scripting (XSS)
352, 79
CWE
Product Name: Ultimate Product Catalogue
Affected Version From: 3.1.2002
Affected Version To: 3.1.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:etoile_web_design:ultimate_product_catalogue
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6, PHP 5.3 with magic_quotes_gpc turned off, Apache 2.4.0 (Ubuntu)
2015
Multiple Persistent XSS & CSRF & File Upload on Ultimate Product Catalogue 3.1.2
Ultimate Product Catalogue is a responsive and easily customizable plugin for all your product catalogue needs. It has +63.000 downloads, +4.000 active installations. Product Name and Description and File Upload formulary of plugin Ultimate Product Catalog lacks of proper CSRF protection and proper filtering. Allowing an attacker to alter a product pressented to a customer or the wordpress administrators and insert XSS in his product name and description. It also allows an attacker to upload a php script though a CSRF due to a lack of file type filtering when uploading it.
Mitigation:
The vendor has released a patch in version 3.1.5 to address this vulnerability.