CVE-2019-19134
Summary
| CVE | CVE-2019-19134 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-26 15:15:00 UTC |
| Updated | 2020-02-27 15:49:00 UTC |
| Description | The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Heroplugins | Hero Maps Premium | All | All | All | All |
| Application | Heroplugins | Hero Maps Premium | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hooper Labs - Adversarial Techniques and Research | MISC | www.hooperlabs.xyz | Exploit, Third Party Advisory |
| Hero Plugins | Home | MISC | heroplugins.com | Product |
| heroplugins.com/changelogs/hmaps/changelog.txt | MISC | heroplugins.com | Release Notes, Vendor Advisory |
| Hero Maps Premium < 2.2.3 - Unauthenticated Reflected Cross-Site Scripting (XSS) | MISC | wpvulndb.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.