vendor:
Participants Database
by:
Benjamin Lim
6,1
CVSS
MEDIUM
Cross Site Scripting (XSS)
79
CWE
Product Name: Participants Database
Affected Version From: 1.7.5.9
Affected Version To: 1.7.5.10
Patch Exists: YES
Related CWE: CVE-2017-14126
CPE: 2.3:a:xnau:participants_database:1.7.5.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0
2017
WordPress Plugin Participants Database < 1.7.5.10 - XSS
Cross site scripting (XSS) vulnerability in the Wordpress Participants Database plugin 1.7.59 allows attackers to inject arbitrary javascript via the Name parameter. The XSS vulnerability is found on the participant signup form input textfield. The get_field_value_display() function in PDb_FormElement.class.php did not escape HTML special characters, allowing an attacker to input javascript. The XSS code will be executed on 2 pages.
Mitigation:
Update to version 1.7.5.10