[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress Training Membership 1.0.8 Cross Site Scripting Vulnerability

Author
8bitsec
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-28465
Category
web applications
Date add
09-09-2017
Platform
php
# Exploit Title: Wordpress Fitness Trainer - Training Membership Plugin <= v1.0.8 - Authenticated Stored/Reflected XSS
# Exploit Author: 8bitsec
# Vendor Homepage: https://codecanyon.net/item/fitness-trainer-training-membership-plugin/19901278
# Software Link: https://codecanyon.net/item/fitness-trainer-training-membership-plugin/19901278
# Version: 1.0.8
# Tested on: [Kali Linux 2.0 | Mac OS 10.12.6]
# Email: contact@8bitsec.io
# Contact: https://twitter.com/_8bitsec

Release Date:
=============
2017-09-07

Product & Service Introduction:
===============================
Fitness Trainer - Training Membership Plugin

Technical Details & Description:
================================

Authenticated Stored XSS vulnerability found on Account Settings section.
Reflected XSS on profile parameter.

Proof of Concept (PoC):
=======================

Authenticated Stored XSS:

Logged as a low priv user.
Account Settings Section. Vulnerable Fields:
First Name
Last Name
Occupation
About
Website URL

Authenticated Reflected XSS on profile parameter:

https://localhost/fitnessp/my-account/?profile=<svg/onload=alert(document.domain)>

==================
8bitsec - [https://twitter.com/_8bitsec]

#  0day.today [2024-11-15]  #