WordPress Plugin Vulnerabilities

Sliced Invoices < 3.8.4 - Multiple Vulnerabilities

Description

- Unauthenticated information disclosure, allowing attackers to access arbitrary invoices and quotes containing PII
- Authenticated SQL injection and information disclosure
- Additional issues, such as lack of CSRF and Authorisation checks on AJAX methods used to search invoices.

- Authenticated Reflected XSS

v3.8.4 also added various sanitisation

Proof of Concept

Affects Plugins

Fixed in 3.8.4

References

Miscellaneous

Original Researcher
Jerome Bruandet (NinTechNet.com)
Verified
No

Timeline

Publicly Published
2019-10-17 (about 6 years ago)
Added
2019-10-17 (about 6 years ago)
Last Updated
2020-09-01 (about 5 years ago)

Other