CVE-2023-0479

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tychesoftwares:print_invoice_\&_delivery_notes_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/50963747-ae8e-42b4-bb42-cc848be7b92e/ - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/50963747-ae8e-42b4-bb42-cc848be7b92e/ - Exploit, Third Party Advisory

22 Jan 2024, 19:50

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/50963747-ae8e-42b4-bb42-cc848be7b92e/ - () https://wpscan.com/vulnerability/50963747-ae8e-42b4-bb42-cc848be7b92e/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:tychesoftwares:print_invoice_\&_delivery_notes_for_woocommerce:*:*:*:*:*:wordpress:*:*
First Time Tychesoftwares print Invoice \& Delivery Notes For Woocommerce
Tychesoftwares
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

16 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 16:15

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0479

Mitre link : CVE-2023-0479

CVE.ORG link : CVE-2023-0479


JSON object : View

Products Affected

tychesoftwares

  • print_invoice_\&_delivery_notes_for_woocommerce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')