// For flags

CVE-2020-35937

Team Showcase <= 1.22.15 - Stored Cross-Site Scripting

Severity Score

8.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

Unas vulnerabilidades de tipo Cross-Site Scripting (XSS) almacenado en el plugin Team Showcase versiones anteriores a 1.22.16 para WordPress, permiten a atacantes autenticados remotos importar diseños, incluyendo JavaScript suministrado por medio de una carga útil diseñada remotamente en el parámetro source por medio de AJAX.&#xa0;La acción debe ser establecida en la función team_import_xml_layouts.

*Credits: Ram
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-09-17 CVE Published
  • 2021-01-01 CVE Reserved
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-09-18 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Pickplugins
Search vendor "Pickplugins"
Post Grid
Search vendor "Pickplugins" for product "Post Grid"
< 2.0.73
Search vendor "Pickplugins" for product "Post Grid" and version " < 2.0.73"
wordpress
Affected
Pickplugins
Search vendor "Pickplugins"
Team Showcase
Search vendor "Pickplugins" for product "Team Showcase"
< 1.22.16
Search vendor "Pickplugins" for product "Team Showcase" and version " < 1.22.16"
wordpress
Affected