vendor:
Wise Chat
by:
MTK
6.1
CVSS
MEDIUM
Reverse Tabnabbing
601
CWE
Product Name: Wise Chat
Affected Version From: 2.6.3
Affected Version To: 2.6.3
Patch Exists: YES
Related CWE: CVE-2019-6780
CPE: a:kaine:wise_chat
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 9 - Apache2 - Wordpress 4.9.8 - Firefox
2019
WordPress Plugin Wisechat <= 2.6.3 - Reverse Tabnabbing
Send a URL on wise chat with a malicious HTML code which silently redirects the parent tab to a phishing site to try gain credentials for users.
Mitigation:
Update to the latest version of the plugin.