mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 14:19:30 +02:00
944 B
944 B
CVE-2021-24973
Description
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
POC
Reference
- https://wpscan.com/vulnerability/0118f245-0e6f-44c1-9bdb-5b3a5d2403d6
- https://wpscan.com/vulnerability/0118f245-0e6f-44c1-9bdb-5b3a5d2403d6
Github
No PoCs found on GitHub currently.