5.5

CVE-2021-24445

Exploit

My Site Audit <= 1.2.4 - Authenticated Stored Cross-Site Scripting (XSS)

My Site Audit <= 1.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting

The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
Mögliche Gegenmaßnahme
My Site Audit: Update to version 1.2.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraftpressMy Site Audit SwPlatformwordpress Version <= 1.2.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt My Site Audit
Version *-1.2.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/d60634a3-ca39-43be-893b-ff9ba625360f
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/13c607d9-a8fe-4a03-972c-d0c1b752c7d8
Third Party Advisory