WordPress Plugin Vulnerabilities
Cerber Limit Login Attempts < 2.7 - Unauthenticated Stored XSS
Description
If the option "I'm behind a proxy" is enabled, the visitor IP is read from X-Forwarded-For header, stored & printed in the admin panel without any sanitization / validation.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Gerard Arall
Submitter website
Verified
No
WPVDB ID
Timeline
Publicly Published
2016-04-01 (about 10 years ago)
Added
2016-04-01 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)