oss-sec mailing list archives

Multiple vulnerabilities affecting two WordPress Plugins (XSS, CSRF & SQLi)


From: Summer of Pwnage <lists () securify nl>
Date: Sat, 28 Jan 2017 16:15:04 +0100

Please see attached advisories for more information. These issues were found during Summer of Pwnage (https://sumofpwn.nl), a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way.

Attachment: cross_site_request_forgery_vulnerability_in_formbuilder_wordpress_plugin_allows_plugin_permissions_modification.txt
Description:

Attachment: multiple_blind_sql_injection_vulnerabilities_in_formbuilder_wordpress_plugin.txt
Description:

Attachment: persistent_cross_site_scripting_vulnerability_in_user_access_manager_wordpress_plugin.txt
Description:


Current thread: