vendor:
Admin Bar & Dashboard Access Control
by:
Rachit Arora
3.1
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Admin Bar & Dashboard Access Control
Affected Version From: 1.2.2008
Affected Version To: 1.2.2008
Patch Exists: NO
Related CWE: CVE-2023-47184
CPE: a:wordpress:admin_bar_and_dashboard_access_control:1.2.8
Platforms Tested: Windows
2023
WordPress Plugin Admin Bar & Dashboard Access Control 1.2.8 Stored Cross-Site Scripting (XSS)
An attacker can inject malicious scripts into the 'Dashboard Redirect' field of WordPress Plugin Admin Bar & Dashboard Access Control version 1.2.8. When a user triggers the stored payload, the injected JavaScript executes, leading to a successful XSS attack.
Mitigation:
To mitigate this vulnerability, sanitize and validate user inputs before storing them in the database.