cleantalk
Vulnerabilities and Security Researches

Social Sharing Plugin – Sassy Social Share, 4631519b-2060-43a0-b69b-b3d7ed94c705

Published on
-
Research Description
Social Sharing Plugin &#8211; Sassy Social Share [sassy-social-share] < 3.3.4 Sassy Social Share &lt;= 3.3.3 - Cross-Site Scripting (XSS) AJAX endpoints which returns JSON data has no Content-Type header set, and uses default text/html. Any JSON that has HTML will be rendered as such.
Affected versions
max 3.3.4.
Status
vulnerable