WordPress Plugin Vulnerabilities
Awesome Support < 6.0.0 - Stored XSS via Ticket Title
Description
The lack of sanitisation in the post_title of a ticket could allow users with the Support Supervisor capability to create tickets containing XSS payloads.
The risk is relatively low, as CSRF checks are in place and the affected role is close to an admin one. Using the DISALLOW_UNFILTERED_HTML
constant does not mitigate the attack.
January 10th, 2020 - WP Plugins Team Notified
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
0xPablito
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2020-01-06 (about 6 years ago)
Added
2020-01-10 (about 6 years ago)
Last Updated
2020-09-22 (about 5 years ago)