Themes Vulnerabilities

Zoner < 4.2 - Persistent XSS & IDOR

Description

----[]- Persistent XSS: -[]----
'Address' input field on the 'Local information' block is vulnerable so you can use your payload to steal admin cookies or do some redirects etc.

----[]- IDOR: -[]----
POST request https://zoner.fruitfulcode.com/wp-admin/admin-ajax.php?action=delete_property_act&property_id=XXX&security=YYY (where XXX is page or post ID and YYY is account security code) will delete any page or post you want.

Proof of Concept

Affects Themes

Fixed in 4.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
m0ze
Submitter
m0ze
Submitter twitter
Verified
No

Timeline

Publicly Published
2019-09-27 (about 6 years ago)
Added
2019-11-03 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other