Duplicator <= 1.2.28 – Unauthenticated Stored Cross-Site Scripting
2017-11-07 00:00
AnonymousStrategic Overview
StatusPatched in 1.2.30
Affected Version
<= 1.2.28CVSS6.1Medium
CVE
CVE-2017-16815Vulnerability Overview
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
Technical Analysis
REMEDIATION: Update to version 1.2.30, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C