Broken Link Checker <= 1.11.8 - Reflected Cross-Site Scripting

2019-10-15 00:00
Anonymous

Strategic Overview

Status
Patched in 1.11.9
Affected PluginBroken Link Checker
Affected Version< 1.11.9
CVSS6.1Medium
CVECVE-2019-16521
View all Broken Link Checker vulnerabilities

Vulnerability Overview

The Broken Link Checker plugin through 1.11.8 for WordPress is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product.

Technical Analysis

REMEDIATION: Update to version 1.11.9, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C