Themes Vulnerabilities

Greenmart < 2.4.3 - Reflected Cross-Site Scripting (XSS)

Description

The greenmart_autocomplete_search AJAX action, available to both authenticated and unauthenticated users does not properly sanitise the callback parameter passed to it, resulting in a reflected Cross-Site Scripting issue.

Edit (WPScanTeam):
The vendor 'fixed' the issue for authenticated users by adding a nonce rather than escaping the callback parameter. However, the issue still remains for unauthenticated users, the vendor has been notified via Envato and another advisory will be released with the details once fixed.

Proof of Concept

Affects Themes

Fixed in 2.4.3

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Cyber Security Works Pvt. Ltd
Verified
Yes

Timeline

Publicly Published
2020-10-28 (about 5 years ago)
Added
2020-10-28 (about 5 years ago)
Last Updated
2020-10-31 (about 5 years ago)

Other