CVE-2019-1010207

Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.
References
Link Resource
https://0day.today/exploit/31255 Third Party Advisory
https://packetstormsecurity.com/files/149665/wppieregister3015-xss.txt Third Party Advisory VDB Entry
https://seclists.org/bugtraq/2018/Oct/16 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:genetechsolutions:pie_register:3.0.15:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2019-07-23 14:15

Updated : 2024-02-04 20:20


NVD link : CVE-2019-1010207

Mitre link : CVE-2019-1010207

CVE.ORG link : CVE-2019-1010207


JSON object : View

Products Affected

genetechsolutions

  • pie_register
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')