Files
CVEs-PoC/2021/CVE-2021-24277.md
T
2024-06-18 02:51:15 +02:00

18 lines
800 B
Markdown

### [CVE-2021-24277](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24277)
![](https://img.shields.io/static/v1?label=Product&message=RSS%20for%20Yandex%20Turbo&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.30%3C%201.30%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen)
### Description
The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues
### POC
#### Reference
- https://wpscan.com/vulnerability/8ebf56be-46c0-4435-819f-dc30370eafa4
#### Github
No PoCs found on GitHub currently.