Логотип exploitDog
bind:CVE-2021-24431
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24431

Количество 2

Количество 2

nvd логотип

CVE-2021-24431

больше 4 лет назад

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32wp-2wg5-3q9c

больше 3 лет назад

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24431

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-32wp-2wg5-3q9c

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу