Record summary

CVE-2024-35694 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 6, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WPMobile.App

Browse Amauri / WPMobile.Appwpappninja

Default status: unaffected

CVE ListThrough 11.41affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordpress WPMobile.App >= 11.42 - Cross-Site ScriptingCVSS 7.1

WPMobile.App versions up to 11.41 contain a reflected cross-site scripting (XSS) caused by improper input neutralization during web page generation, letting attackers execute scripts in the victim's browser, exploit requires attacker to craft malicious input.

Impact

Attackers can execute arbitrary scripts in the victim's browser, potentially stealing cookies, session tokens, or performing actions on behalf of the user.

Remediation

Implement proper input sanitization and output encoding, and update to the latest version of WPMobile.App.

WeaknessesCWE-79
AuthorsSourabh-Sahu
Template tagscvecve2024xsswpwordpresswpmobileappwp-pluginvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CPE: cpe:2.3:a:amauri:wpmobile.app:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/wpappninja"
FOFA: body="/wp-content/plugins/wpappninja"
Google: inurl:"/wp-content/plugins/wpappninja"

Source: ProjectDiscovery

References

3