CVE-2021-24176

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jh_404_logger_project:jh_404_logger:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 05:52

Type Values Removed Values Added
References () https://ganofins.com/blog/my-first-cve-2021-24176/ - Exploit, Third Party Advisory () https://ganofins.com/blog/my-first-cve-2021-24176/ - Exploit, Third Party Advisory
References () https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585 - Exploit, Third Party Advisory

18 Oct 2021, 12:06

Type Values Removed Values Added
References (MISC) https://ganofins.com/blog/my-first-cve-2021-24176/ - (MISC) https://ganofins.com/blog/my-first-cve-2021-24176/ - Exploit, Third Party Advisory

29 Sep 2021, 11:15

Type Values Removed Values Added
References
  • (MISC) https://ganofins.com/blog/my-first-cve-2021-24176/ -

Information

Published : 2021-04-05 19:15

Updated : 2024-11-21 05:52


NVD link : CVE-2021-24176

Mitre link : CVE-2021-24176

CVE.ORG link : CVE-2021-24176


JSON object : View

Products Affected

jh_404_logger_project

  • jh_404_logger
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')