[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress Job Manager Plugin 0.7.22 - Persistent XSS Vulnerability

Author
Owais Mehtab
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-23989
Category
web applications
Date add
09-08-2015
CVE
CVE-2015-2321
Platform
php
Job Manager Persistent XSS
 
Details
========================================================================================
Product: Job Manager Plugin For Wordpress
Vendor-URL: www.wp-jobmanager.com
CVE-ID: CVE-2015-2321
 
 
Credits
========================================================================================
Discovered by: Owais Mehtab
 
 
Affected Products:
========================================================================================
Job Manager Plugin <= 0.7.22
 
Description
========================================================================================
"Job Manager Plugin For Wordpress"
 
More Details
========================================================================================
A persistent Cross site scripting (XSS) in Job Manager Plugin has been discovered,
the plugin's email field was not sanitized thus the vulnerability can be easily 
exploited and can be used to steal cookies,perform phishing attacks and other various 
attacks compromising the security of a user.
 
Proof of Concept
========================================================================================
Click on the "send through your résume" and set the below vector in email field
 
'"><img src=x onerror=prompt(document.cookie);>
 
Now click on initiate chat 
 
PoC Video
https://www.dropbox.com/s/i8cuf15hbdf5tmu/jobmanager-xss.mp4

#  0day.today [2024-11-16]  #