mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 12:01:39 +02:00
903 B
903 B
CVE-2021-24421
Description
The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue
POC
Reference
- https://wpscan.com/vulnerability/b378d36d-66d9-4373-a628-e379e4766375
- https://wpscan.com/vulnerability/b378d36d-66d9-4373-a628-e379e4766375
Github
No PoCs found on GitHub currently.