Loading HuntDB...

Multiple XSS in Camptix Event Ticketing Plugin

I
Ian Dunn
Submitted None
Reported by thezawad

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Hi, As discussed in #151561 submitting the report here. I have got some more bugs in Camptix Event Ticketing plugin. Well, the first one is a ticket page xss caused by the **Ticket Title** And the second one is kind of self-xss, caused by also the **Ticket title** of the plugin but in the coupons page. I have added a video *PoC* for your clarification with step by step reproduction. As I have seen in #9391 you've fixed self-xss, I have created this report. I think both of the bugs should be fixed. I expect you fix both of them. https://drive.google.com/open?id=0B0Ah8VhxGMynZXUwbGlaMm5iVDQ -------- Zawad

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic