Description
WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
strider
References
www.exploit-db.com/exploits/47419 (ExploitDB-47419)
github.com/anttiviljami/wp-server-log-viewer (WP Server Log Viewer GitHub Repository)
www.vulncheck.com/...logfile-persistent-cross-site-scripting (VulnCheck Advisory: WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting)