Skip to content

Latest commit

 

History

History
11 lines (11 loc) · 787 Bytes

WpGenius Job Listing.md

File metadata and controls

11 lines (11 loc) · 787 Bytes

Exploit Title: WrodPress Plugin WpGenius Job Listing ——"Settings" Stored Cross-Site Scripting

Exploit Author: Thinkland Security Team

Version : V 1.0.2

Vulnerability Type: Stored Cross-Site Scripting

Tested on Windows 10 、XAMPP

Vulnerability proof:

  1. Job Listing 》 Settings 》General》Default message for ( no job ) ,insert the xss payload "OnMoUsEoVeR=prompt(1)// image
  2. Job Listing 》 Settings 》E-mail notifications》Reply-To and Subject,insert the xss payload "OnMoUsEoVeR=prompt(1)// image