n the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.
| Link | Resource |
|---|---|
| https://plugins.svn.wordpress.org/gtranslate/tags/2.8.64/gtranslate.php | Exploit Third Party Advisory |
| https://plugins.svn.wordpress.org/gtranslate/tags/2.8.64/gtranslate.php | Exploit Third Party Advisory |
Configuration 1 (hide)
|
21 Nov 2024, 06:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://plugins.svn.wordpress.org/gtranslate/tags/2.8.64/gtranslate.php - Exploit, Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 5.0 |
Published : 2021-07-30 21:15
Updated : 2024-11-21 06:10
NVD link : CVE-2021-34630
Mitre link : CVE-2021-34630
CVE.ORG link : CVE-2021-34630
JSON object : View