WordPress WP-TopBar Plugin HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:55603
Info
WordPress WP-TopBar Plugin HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 55603 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2012 12:00AM |
| Updated: | Sep 19 2012 12:00AM |
| Credit: | Blake Entrekin |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress WP-TopBar Plugin HTML Injection and Cross Site Request Forgery Vulnerabilities
The WP-TopBar plugin for WordPress is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
WP-TopBar 4.02 is vulnerable; prior versions may also be affected.
The WP-TopBar plugin for WordPress is prone to an HTML-injection vulnerability and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
WP-TopBar 4.02 is vulnerable; prior versions may also be affected.
References
WordPress WP-TopBar Plugin HTML Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- WordPress WP-TopBar Plugin Changelog (WordPress)
- WordPress WP-TopBar Plugin HomePage (WordPress)