Hi Author,
Last week we conduct a pentest on one of our site that using betheme version 10.7 and wordpress version 4.4.1. Found that betheme is vulnerable to XSS which may potentially allow attacker send undesirable content to user such as modified content and script.
And then to see the XSS error , do browse this URL using Internet Explorer 11:
[Links visible only for registered users]?"><body/**/onload=eval(String.fromCharCode(97,108,101,114,116,40,39,77,97,108,105,99,105,111,117,115,32,67,111,100,101,32,69,120,101,99,117,116,101,100,39,41,59))></body>
htaccess Username: demo
htaccess Password: demo
When run above url, will see error message "Internet Explorer has modified this page to help prevent cross-site-scripting' prompted at the bottom of the browser. Refer screen shot of the error here: [Links visible only for registered users]
Please check and let us know the fixes soon as this is the major security flaw.
Thank you.
Comments