blog.nintechnet.com
https://blog.nintechnet.com/unauthenticated-stored-xss-vulnerability-in-wordpress-onetone-theme-unpatched CVE-2019-17231
MEDIUMNuclei
mageewp onetone Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2019-17231 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 15, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
onetoneBrowse mageewp / onetone | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSSCVSS 6.1
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
Impact
Unauthenticated attackers can inject malicious JavaScript that will be stored and executed when users visit the site, potentially stealing cookies, credentials, or performing actions on behalf of all site visitors.
Remediation
Update the OneTone theme to version 3.0.7 or later, or switch to a different theme.
Authorsdaffainfo
Template tagscvecve2019wordpresswp-themewponetonexssintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:mageewp:onetone:*:*:*:*:*:wordpress:*:*
https://blog.sucuri.net/2020/04/onetone-vulnerability-leads-to-javascript-cookie-hijacking.html https://blog.nintechnet.com/unauthenticated-stored-xss-vulnerability-in-wordpress-onetone-theme-unpatched/ https://nvd.nist.gov/vuln/detail/CVE-2019-17231
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17231