5.4

CVE-2021-24156

Exploit

Testimonial Rotator <= 3.0.3 - Authenticated Stored Cross-Site Scripting

Testimonial Rotator <= 3.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
Mögliche Gegenmaßnahme
Testimonial Rotator: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Testimonial Rotator ProjectTestimonial Rotator Version3.0.3 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Testimonial Rotator
Version *-3.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.478
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://mega.nz/file/ftVSmRCC#ctqUg89CKszEuLO3eeQVazUStTPvoQD6LlbWNSMa7uA
Third Party Advisory
Exploit
https://wpscan.com/vulnerability/8b6f4a77-4008-4730-9a91-fa055a8b3e68
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/0ea0f826-5ae9-4dad-89d0-9fc9f10f526b
Third Party Advisory