.. / CVE-2020-26153

Exploit for Event Espresso Core-Reg 4.10.7.p - Cross-Site Scripting (CVE-2020-26153)

Description:

Event Espresso Core-Reg 4.10.7.p is vulnerable to cross-site scripting in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php and allows remote attackers to inject arbitrary web script or HTML via the page parameter.

Nuclei Template

View the template here CVE-2020-26153.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-26153.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://labs.nettitude.com/blog/cve-2020-26153-event-espresso-core-cross-site-scripting/
https://nvd.nist.gov/vuln/detail/CVE-2020-26153
https://github.com/ARPSyndicate/kenzer-templates
https://github.com/eventespresso/event-espresso-core/compare/4.10.6.p...4.10.7.p