> CVE-2021-24495: Improper Neutralization of Input During Web Page Generation on ‘id’ parameter in Wordpress Marmoset Viewer Plugin versions 1.9.3 ≤ leads to Reflected Cross Site Scripting
[DATE: 06/07/2021 01:00]
[LANGUAGE: EN]
Credits John
Github: https://github.com/johnjhacking
Jackson Henry [Helped simplify the payload]
Twitter: https://twitter.com/JacksonHHax
Wabaf3t [Provided post-code analysis/looked for escalation]
Twitter: https://twitter.com/wabafet1
Kelly Kaoudis [Reviewed the writeup]
Twitter: https://twitter.com/kaoudis
Robert Willis [Reviewed the writeup]
Twitter: https://twitter.com/rej_ex
Erwan [Identified bypass]
Twitter: https://twitter.com/erwan_lr
Identification During research, a marmoset viewer was identified as running on a WordPress application. The URL looks like this:
https://example.com/wp-content/plugins/marmoset-viewer/mviewer.php?width=640&height=360&autostart=1&transparantbg=1&nui=1&id=https:/example.com/wp-content/uploads/2020/02/Golems_v2.mview
As seen, there are several parameters, however, while viewing the code on the main page, you can see the following: