Stored XSS Vulnerability in Schiocco Support Board Plugin for WordPress
CVE-2018-18373

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
17 October 2018

Summary

The Schiocco 'Support Board' plugin version 1.2.3 for WordPress contains a vulnerability that allows stored Cross-Site Scripting (XSS) attacks. This vulnerability is specifically found in the file upload areas within the Chat and Help Desk sections. Attackers can exploit a flaw in the msg parameter through the admin-ajax.php endpoint using the sb_ajax_add_message action, potentially gaining the ability to execute arbitrary JavaScript code in the context of a user's session. This can lead to unauthorized actions and data exposure. It is crucial for site administrators using this plugin to apply the necessary security patches to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.