WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
BID:54350
Info
WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
| Bugtraq ID: | 54350 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2012 12:00AM |
| Updated: | Jul 09 2012 12:00AM |
| Credit: | Computing centre of the city of Vienna. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
The Leaflet Maps Marker plugin for WordPress is prone to a cross-site scripting vulnerability, an SQL-injection vulnerability, and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Leaflet Maps Marker versions prior to 2.4 are vulnerable.
The Leaflet Maps Marker plugin for WordPress is prone to a cross-site scripting vulnerability, an SQL-injection vulnerability, and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Leaflet Maps Marker versions prior to 2.4 are vulnerable.
Exploit / POC
WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
References:
References: