CVE-2023-7246
System Dashboard < 2.8.10 - XSS via Header Injection
Record summary
CVE-2023-7246 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
System DashboardDefault status: unaffected | CVE List | Before 2.8.10 | affected |
system_dashboardBrowse bowo / system_dashboardDefault status: unknown | CVE List | Before 2.8.10 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSystem Dashboard < 2.8.10 - Cross-Site ScriptingCVSS 5.4
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks through header injection, specifically in the X-Forwarded-For header.
Impact
Authenticated administrators in multisite WordPress configurations can inject malicious JavaScript through X-Forwarded-For header to execute attacks against other WordPress users.
Remediation
Update the System Dashboard plugin to version 2.8.10 or later.
Source: ProjectDiscovery