PT-2019-11473 · Webappick+1 · Webappick Woocommerce Product Feed+1
CVE-2019-1010124
·
Publicado
2019-07-23
·
Atualizado
2023-02-28
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WebAppick WooCommerce Product Feed versions 2.2.18 and earlier
Description:
The issue allows for Cross Site Scripting (XSS) which can lead to Remote Code Execution (RCE) via editing theme files in WordPress. This is possible when an administrator is logged in. The vulnerable component is located in the
admin/partials/woo-feed-manage-list.php file at line 63.Recommendations:
For WebAppick WooCommerce Product Feed versions 2.2.18 and earlier, update to a version later than 2.2.18 to resolve the issue.
Exploit
Correção
RCE
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webappick Woocommerce Product Feed
Wordpress