CVE-2017-9288
MEDIUMNuclei
WordPress Raygun4WP <=1.8.0 - Cross-Site Scripting
Record summary
CVE-2017-9288 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.
Proofs of concept
2Curated repository PoCs
GitHubCVE-2017-9288Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2017-9288Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Raygun4WP <=1.8.0 - Cross-Site ScriptingCVSS 6.1
WordPress Raygun4WP 1.8.0 contains a reflected cross-site scripting vulnerability via sendtesterror.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update to the latest version of the WordPress Raygun4WP plugin (1.8.0 or higher) to mitigate this vulnerability.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2017cvewordpressxsswp-pluginraygunvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:raygun:raygun4wp:1.8.0:*:*:*:*:wordpress:*:*
https://github.com/MindscapeHQ/raygun4wordpress/pull/17 https://github.com/MindscapeHQ/raygun4wordpress/issues/16 http://jgj212.blogspot.kr/2017/05/a-reflected-xss-vulnerability-in.html https://nvd.nist.gov/vuln/detail/CVE-2017-9288 https://wpvulndb.com/vulnerabilities/8836
Source: ProjectDiscovery
References
5jgj212.blogspot.kr
http://jgj212.blogspot.kr/2017/05/a-reflected-xss-vulnerability-in.html github.com
https://github.com/MindscapeHQ/raygun4wordpress/issues/16 github.com
https://github.com/MindscapeHQ/raygun4wordpress/pull/17 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9288 wpvulndb.com
https://wpvulndb.com/vulnerabilities/8836