vendor:
Usernoise
by:
Nikolay Karev
8,8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Usernoise
Affected Version From: 3.7.8
Affected Version To: 3.7.8
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:wordpress:usernoise
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Wordpress
2013
Unauthorized persistent cross-site scripting in Usernoise
The summary field in Usernoise is vulnerable to persistent cross site scripting, and the affected area is the Wordpress admin dashboard. The reason why this vulnerability exists is because the user input is not being properly handled when a feedback is submitted. It accepts any type of arbitrary code, including JavaScript, and when the content is displayed in the feedback section in the dashboard, all JavaScript code is executed causing a sever vulnerability with administrators as the target.
Mitigation:
Upgrade to plugin version 3.7.9