mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-10 20:04:58 +02:00
1.1 KiB
1.1 KiB
CVE-2021-24736
Description
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.
POC
Reference
- https://wpscan.com/vulnerability/d72275bd-0c66-4b2a-940d-d5256b5426cc
- https://wpscan.com/vulnerability/d72275bd-0c66-4b2a-940d-d5256b5426cc