Stored XSS Vulnerability in Schiocco Support Board Plugin for WordPress
CVE-2018-18373
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 October 2018
What is CVE-2018-18373?
The Schiocco 'Support Board' plugin version 1.2.3 for WordPress contains a vulnerability that allows stored Cross-Site Scripting (XSS) attacks. This vulnerability is specifically found in the file upload areas within the Chat and Help Desk sections. Attackers can exploit a flaw in the msg parameter through the admin-ajax.php endpoint using the sb_ajax_add_message action, potentially gaining the ability to execute arbitrary JavaScript code in the context of a user's session. This can lead to unauthorized actions and data exposure. It is crucial for site administrators using this plugin to apply the necessary security patches to mitigate risks associated with this vulnerability.