CVE-2018-1002005
MEDIUMArigato Autoresponder and Newsletter 2.5.0-2.5.1.4 - Stored XSS via filter_signup_date
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1002005. PoCs published by Larry W. Cashdollar.
AI-analyzed exploit summary The document describes multiple vulnerabilities (SQLi and XSS) in the WordPress plugin Arigato Autoresponder and Newsletter v2.5, including a blind SQL injection via the 'del_ids' parameter and nine reflected XSS vulnerabilities. It provides details on the vulnerable code lines and includes an example of using sqlmap to exploit the SQL injection.
Description
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.
Exploits (1)
The document describes multiple vulnerabilities (SQLi and XSS) in the WordPress plugin Arigato Autoresponder and Newsletter v2.5, including a blind SQL injection via the 'del_ids' parameter and nine reflected XSS vulnerabilities. It provides details on the vulnerable code lines and includes an example of using sqlmap to exploit the SQL injection.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N