Record summary

CVE-2018-20462 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2018-20462Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 474 B

GitHub

PoC details
GitHubCVE-2018-20462Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 474 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress JSmol2WP <=1.07 - Cross-Site ScriptingCVSS 6.1

WordPress JSmol2WP version 1.07 and earlier is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update to the latest version of the WordPress JSmol2WP plugin (1.08 or higher) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2018cvewordpressxsswp-pluginjsmol2wp_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jsmol2wp_project:jsmol2wp:1.07:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3