The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
History

Mon, 07 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Squirrly
Squirrly starbox
Weaknesses CWE-79
CPEs cpe:2.3:a:squirrly:starbox:*:*:*:*:*:wordpress:*:*
Vendors & Products Squirrly
Squirrly starbox

Tue, 01 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Squirrlyuk
Squirrlyuk starbox
CPEs cpe:2.3:a:squirrlyuk:starbox:*:*:*:*:*:*:*:*
Vendors & Products Squirrlyuk
Squirrlyuk starbox
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
Title Starbox < 3.5.3 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-30T06:00:06.516Z

Updated: 2024-10-01T13:58:54.159Z

Reserved: 2024-08-27T18:59:09.028Z

Link: CVE-2024-8239

cve-icon Vulnrichment

Updated: 2024-10-01T13:58:40.692Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-30T06:15:14.520

Modified: 2024-10-07T15:48:35.887

Link: CVE-2024-8239

cve-icon Redhat

No data.