vendor:
WP-Client
by:
Pier-Luc Maltais
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: WP-Client
Affected Version From: 3.8.7
Affected Version To: 1.5.1
Patch Exists: YES
Related CWE: None
CPE: a:wp-client:wp-client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
WP-Client Vulnerability
WP-Client is vulnerable to a stored XSS attack in the Request Estimate page. The extension affected is Estimates/Invoices v1.5.1. An attacker can inject malicious JavaScript code in the 'Comments' field of the Request Estimate page, which will be executed when the page is viewed by an administrator.
Mitigation:
Update to the latest version of WP-Client (v3.8.7) and the Estimates/Invoices extension (v1.5.2).