Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24245

Опубликовано: 06 мая 2021
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Средний

Описание

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trumani:stop_spammers:*:*:*:*:*:wordpress:*:*
Версия до 2021.9 (исключая)

EPSS

Процентиль: 95%
0.17943
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

EPSS

Процентиль: 95%
0.17943
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79