PT-2018-12508 · Mondula · Mondula Multi Step Form

Javier Olmedo

·

Publicado

2018-07-25

·

Atualizado

2018-09-21

·

CVE-2018-14430

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mondula Multi Step Form plugin versions prior to 1.2.6
Description The issue allows for XSS exploitation via specific fields in the contact form, including fw data [id][1], fw data [id][2], fw data [id][3], fw data [id][4], or the email field. This can be exploited using an fw send email action to the "/wp-admin/admin-ajax.php" API endpoint.
Recommendations For Mondula Multi Step Form plugin versions prior to 1.2.6, update to version 1.2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the contact form fields fw data [id][1], fw data [id][2], fw data [id][3], fw data [id][4], and email to minimize the risk of exploitation. Avoid using the fw send email action to the "/wp-admin/admin-ajax.php" API endpoint until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14430
MGASA-2018-0388

Produtos afetados

Mondula Multi Step Form