WordPress Plugin Vulnerabilities

Cerber Limit Login Attempts < 2.7 - Unauthenticated Stored XSS

Description

If the option "I'm behind a proxy" is enabled, the visitor IP is read from X-Forwarded-For header, stored & printed in the admin panel without any sanitization / validation.

Proof of Concept

Affects Plugins

Fixed in 2.7

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Gerard Arall
Submitter website
Verified
No

Timeline

Publicly Published
2016-04-01 (about 10 years ago)
Added
2016-04-01 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other