CVE-2019-20204
MEDIUMPostie < 1.9.40 - Cross-Site Scripting via SVG Element
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-20204. PoCs published by V1n1v131r4.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in WordPress Plugin Postie 1.9.40 via a crafted SVG payload. It includes steps for identifying the plugin, enumerating email accounts, and spoofing emails using PHPMailer.
Description
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in WordPress Plugin Postie 1.9.40 via a crafted SVG payload. It includes steps for identifying the plugin, enumerating email accounts, and spoofing emails using PHPMailer.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N