knassar702.github.io
https://knassar702.github.io/cve/neon CVE-2019-20141
MEDIUMNuclei
WordPress Laborator Neon Theme 2.0 - Cross-Site Scripting
Record summary
CVE-2019-20141 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Laborator Neon Theme 2.0 - Cross-Site ScriptingCVSS 6.1
WordPress Laborator Neon theme 2.0 contains a cross-site scripting vulnerability via the data/autosuggest-remote.php q parameter.
Impact
Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing administrative actions on behalf of users.
Remediation
Apply the latest security patch or update provided by the theme developer to fix the XSS vulnerability.
WeaknessesCWE-79
Authorsknassar702
Template tagscve2019cvexsslaboratorwordpressvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:laborator:neon:2.0:*:*:*:*:wordpress:*:*
https://knassar7o2.blogspot.com/2019/12/neon-dashboard-cve-2019-20141.html https://knassar7o2.blogspot.com/2019/12/neon-dashboard-xss-reflected.html https://knassar702.github.io/cve/neon/ https://nvd.nist.gov/vuln/detail/CVE-2019-20141 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3knassar7o2.blogspot.com
https://knassar7o2.blogspot.com/2019/12/neon-dashboard-xss-reflected.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-20141