6.1

CVE-2021-24756

Exploit

WP System Log < 1.0.21 - Unauthenticated Stored Cross-Site Scripting

WP System Log < 1.0.21 - Cross-Site Scripting

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.
Mögliche Gegenmaßnahme
Activity Log for WordPress: Update to version 1.0.21, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wp System Log ProjectWp System Log SwPlatformwordpress Version < 1.0.21
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Activity Log for WordPress
Version [*, 1.0.21)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.672
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/0cea0717-8f54-4f1c-b3ee-aff7dd91bf59
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/f5733a60-8078-48ed-9395-ea79b4199f7e
Third Party Advisory