Логотип exploitDog
bind:CVE-2021-24756
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24756

Количество 2

Количество 2

nvd логотип

CVE-2021-24756

около 4 лет назад

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-x547-6pg3-h56r

около 4 лет назад

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24756

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

CVSS3: 6.1
15%
Средний
около 4 лет назад
github логотип
GHSA-x547-6pg3-h56r

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

15%
Средний
около 4 лет назад

Уязвимостей на страницу