Multiple XSS in Camptix Event Ticketing Plugin
I
Ian Dunn
Submitted None
Actions:
Reported by
thezawad
Vulnerability Details
Technical details and impact analysis
Hi,
As discussed in #151561 submitting the report here.
I have got some more bugs in Camptix Event Ticketing plugin.
Well, the first one is a ticket page xss caused by the **Ticket Title**
And the second one is kind of self-xss, caused by also the **Ticket title** of the plugin but in the coupons page.
I have added a video *PoC* for your clarification with step by step reproduction.
As I have seen in #9391 you've fixed self-xss, I have created this report.
I think both of the bugs should be fixed.
I expect you fix both of them.
https://drive.google.com/open?id=0B0Ah8VhxGMynZXUwbGlaMm5iVDQ
--------
Zawad
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic