4
CVSSv2

CVE-2014-9179

Published: 02/12/2014 Updated: 03/12/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.

Vulnerable Product Search on Vulmon Subscribe to Product

supportezzy ticket system project supportezzy ticket system 1.2.5

Exploits

# Exploit Title: SupportEzzy Ticket System - WordPress Plugin Stored XSS Vulnerability # Date: 12-10-2014 # Exploit Author: Halil Dalabasmaz # Version: v125 # Vendor Homepage: codecanyonnet/item/supportezzy-ticket-system-wordpress-plugin/8908617 # Software Test Link: democssjockeycom/cjsupport/supportezzy/ # Tested on: Iceweasel ...