WordPress Google Maps Plugin CVE-2018-0577 Cross Site Scripting Vulnerability
BID:108472
Info
WordPress Google Maps Plugin CVE-2018-0577 Cross Site Scripting Vulnerability
| Bugtraq ID: | 108472 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-0577 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2018 12:00AM |
| Updated: | Apr 27 2018 12:00AM |
| Credit: | Chris Liu. |
| Vulnerable: |
WordPress Google Maps 3.2 WordPress Google Maps 3.0.9 WordPress Google Maps 3.0 WordPress Google Maps 2.2 WordPress Google Maps 2.1 WordPress Google Maps 1.2 WordPress Google Maps 1.1 WordPress Google Maps 4.0.3 WordPress Google Maps 4.0.0 WordPress Google Maps 3.1.6 WordPress Google Maps 3.1.0 WordPress Google Maps 3.0.5 WordPress Google Maps 2.3.7 |
| Not Vulnerable: |
WordPress Google Maps 4.0.4 |
Discussion
WordPress Google Maps Plugin CVE-2018-0577 Cross Site Scripting Vulnerability
The Google Map Plugin for WordPress is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Google Maps plugin 4.0.4 are vulnerable.
The Google Map Plugin for WordPress is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Google Maps plugin 4.0.4 are vulnerable.
Exploit / POC
WordPress Google Maps Plugin CVE-2018-0577 Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
WordPress Google Maps Plugin CVE-2018-0577 Cross Site Scripting Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
WordPress Google Maps Plugin CVE-2018-0577 Cross Site Scripting Vulnerability
References:
References: