Files
CVEs-PoC/2021/CVE-2021-24298.md
T
2024-05-25 21:48:12 +02:00

20 lines
942 B
Markdown

### [CVE-2021-24298](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24298)
![](https://img.shields.io/static/v1?label=Product&message=Simple%20Giveaways%20%E2%80%93%20Grow%20your%20business%2C%20email%20lists%20and%20traffic%20with%20contests&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=2.36.2%3C%202.36.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen)
### Description
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
### POC
#### Reference
- https://codevigilant.com/disclosure/2021/wp-plugin-giveasap-xss/
- https://wpscan.com/vulnerability/30aebded-3eb3-4dda-90b5-12de5e622c91
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates