mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-13 01:44:43 +02:00
18 lines
764 B
Markdown
18 lines
764 B
Markdown
### [CVE-2021-24587](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24587)
|
|

|
|

|
|
&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/bb5d94ad-e1ce-44e2-8403-d73fe75a146a
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|