WP Symposium Pro Social Network Plugin XSS Vulnerability

##FULL DISCLOSURE

#Product : WP Symposium Pro Social Network plugin
#Exploit Author : Rahul Pratap Singh
#Version   : 16.1
#Twitter   : @0x62626262

#Date  : 12/Jan/2016

XSS Vulnerability:

Description:

“user_id” parameter is not sanitized, that leads to reflected xss.

POC:

wpsymposiumpro16_1xsspoc

Fix:
Update to version 16.01.01

Disclosure Timeline:

reported to vendor  : 12/1/2016
vendor response     : 12/1/2016
vendor acknowledged : 12/1/2016
vendor deployed a patch: 12/1/2016

Pub Ref:
https://wordpress.org/plugins/wp-symposium-pro/

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s