vendor:
Video Synchro PDF
by:
UnD3sc0n0c1d0
9.8
CVSS
CRITICAL
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: Video Synchro PDF
Affected Version From: 1.7.2004
Affected Version To: 1.7.2004
Patch Exists: NO
Related CWE:
CPE: a:aj_evolution:video_synchro_pdf
Platforms Tested: CentOS / WordPress 5.9.3
2022
WordPress Plugin Videos sync PDF 1.7.4 – Stored Cross Site Scripting (XSS)
The plugin does not properly sanitize the nom, pdf, mp4, webm and ogg parameters, allowing potentially dangerous characters to be inserted. This includes the reported payload, which triggers a persistent Cross-Site Scripting (XSS).
Mitigation:
Sanitize the nom, pdf, mp4, webm and ogg parameters.