mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-29 20:39:28 +02:00
18 lines
923 B
Markdown
18 lines
923 B
Markdown
### [CVE-2021-24994](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24994)
|
|

|
|

|
|
&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1da
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|