CVE-2018-19287
MEDIUM NUCLEINinja Forms < 3.3.18 - Cross-Site Scripting via Submissions Page Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19287. PoCs published by MTK. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in WordPress Ninja Forms plugin up to version 3.3.17. The PoC provides three URLs with injected JavaScript payloads that trigger alerts when executed in the context of the WordPress admin panel.
Description
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in WordPress Ninja Forms plugin up to version 3.3.17. The PoC provides three URLs with injected JavaScript payloads that trigger alerts when executed in the context of the WordPress admin panel.
Nuclei Templates (1)
http.html:/wp-content/plugins/ninja-forms/
body=/wp-content/plugins/ninja-forms/
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N