mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 01:49:30 +02:00
943 B
943 B
CVE-2021-24679
Description
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
POC
Reference
- https://wpscan.com/vulnerability/7c6c0aac-1733-4abc-8e95-05416636a127
- https://wpscan.com/vulnerability/7c6c0aac-1733-4abc-8e95-05416636a127
Github
No PoCs found on GitHub currently.