The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/postman-smtp/#developers | Third Party Advisory |
https://www.pluginvulnerabilities.com/2017/06/29/reflected-cross-site-scripting-xss-vulnerability-in-postman-smtp/ | Exploit Third Party Advisory |
https://wordpress.org/plugins/postman-smtp/#developers | Third Party Advisory |
https://www.pluginvulnerabilities.com/2017/06/29/reflected-cross-site-scripting-xss-vulnerability-in-postman-smtp/ | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 03:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://wordpress.org/plugins/postman-smtp/#developers - Third Party Advisory | |
References | () https://www.pluginvulnerabilities.com/2017/06/29/reflected-cross-site-scripting-xss-vulnerability-in-postman-smtp/ - Exploit, Third Party Advisory |
Information
Published : 2019-09-10 12:15
Updated : 2024-11-21 03:20
NVD link : CVE-2017-18603
Mitre link : CVE-2017-18603
CVE.ORG link : CVE-2017-18603
JSON object : View
Products Affected
postman-smtp_project
- postman-smtp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')