The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
References
Link | Resource |
---|---|
https://ganofins.com/blog/my-first-cve-2021-24176/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585 | Exploit Third Party Advisory |
https://ganofins.com/blog/my-first-cve-2021-24176/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://ganofins.com/blog/my-first-cve-2021-24176/ - Exploit, Third Party Advisory | |
References | () https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585 - Exploit, Third Party Advisory |
18 Oct 2021, 12:06
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://ganofins.com/blog/my-first-cve-2021-24176/ - Exploit, Third Party Advisory |
29 Sep 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2021-04-05 19:15
Updated : 2024-11-21 05:52
NVD link : CVE-2021-24176
Mitre link : CVE-2021-24176
CVE.ORG link : CVE-2021-24176
JSON object : View
Products Affected
jh_404_logger_project
- jh_404_logger
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')