CVE-2019-1010124

WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webappick:woocommerce_product_feed:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 04:17

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/154263/WordPress-WooCommerce-Product-Feed-2.2.18-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/154263/WordPress-WooCommerce-Product-Feed-2.2.18-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References () https://wpvulndb.com/vulnerabilities/9856 - Third Party Advisory () https://wpvulndb.com/vulnerabilities/9856 - Third Party Advisory
References () https://www.youtube.com/watch?v=T-sqQDFRRBg - Exploit, Third Party Advisory () https://www.youtube.com/watch?v=T-sqQDFRRBg - Exploit, Third Party Advisory

28 Feb 2023, 19:23

Type Values Removed Values Added
References
  • {'url': 'http://104.207.151.48/woo-feed-manage-list.php', 'name': 'http://104.207.151.48/woo-feed-manage-list.php', 'tags': ['Broken Link'], 'refsource': 'MISC'}
References (MISC) http://packetstormsecurity.com/files/154263/WordPress-WooCommerce-Product-Feed-2.2.18-Cross-Site-Scripting.html - (MISC) http://packetstormsecurity.com/files/154263/WordPress-WooCommerce-Product-Feed-2.2.18-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) https://wpvulndb.com/vulnerabilities/9856 - (MISC) https://wpvulndb.com/vulnerabilities/9856 - Third Party Advisory
CVSS v2 : 4.3
v3 : 6.1
v2 : 3.5
v3 : 5.4

Information

Published : 2019-07-23 13:15

Updated : 2024-11-21 04:17


NVD link : CVE-2019-1010124

Mitre link : CVE-2019-1010124

CVE.ORG link : CVE-2019-1010124


JSON object : View

Products Affected

webappick

  • woocommerce_product_feed
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')