## FULL DISCLOSURE
#Product : cm-ad-changer
#Exploit Author : Rahul Pratap Singh
#Version :1.7.2
#Home page Link : https://wordpress.org/plugins/cm-ad-changer/
#Website : 0x62626262.wordpress.com
#Linkedin : https://in.linkedin.com/in/rahulpratapsingh94
#Date : 21/4/2016
XSS Vulnerability:
----------------------------------------
Description:
----------------------------------------
Following parameters are not sanitized that leads to XSS Vulnerability.
title, comment, link
----------------------------------------
Vulnerable Code:
----------------------------------------
File Name: testfiles/cm-ad-changer/backend/views/admin_settings.php
Found at line:61
/>
Found at line:73
File Name: testfiles/cm-ad-changer/backend/views/admin_campaigns.php
Found at line:96
----------------------------------------
POC:
----------------------------------------
https://0x62626262.files.wordpress.com/2016/04/cm-ad-changer-xss-poc.png
https://0x62626262.files.wordpress.com/2016/04/cm-ad-changer-xss-poc1.png
Fix:
Update to 1.7.6
Vulnerability Disclosure Timeline:
→ March 14, 2016 – Bug discovered, initial report to Vendor.
→ March 22, 2016 – No Response. Report sent again.
→ March 23, 2016 – WordPress Acknowledged.
→ April 21, 2016 – Full Disclosure.
Pub Ref:
https://0x62626262.wordpress.com/2016/04/21/cm-ad-changer-xss-vulnerability/
https://ad-changer.cminds.com/cm-ad-changer-plugin-free-edition-release-notes/