stored SELF xss on Basic Google Maps Placemarks Settings plugin
I
Ian Dunn
Submitted None
Actions:
Reported by
b6117130df17feef13481e3
Vulnerability Details
Technical details and impact analysis
Hi Ian,
I have to say, normally I don't report and vendors doesn't accept self xss vulnerabilities as valid, but I'm encouraged by #9375
So, I'm reporting this.
Placemark title field is NOT sanitizing the user input properly.
I've updated wordpress to latest, and checked your plugin's versiyon from SVN also, it is latest, too. You can confirm in the attached PoC Screenshots.
Thanks for giving opportunity to test your plugins! Keep up good work.
If you don't find this report useful for you, you can just close it as informative or whatever you like.
Regards
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
Cross-site Scripting (XSS) - Generic