The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to gain unauthorised access by using an XSS payload to create a rogue administrator account, which will be trigged when an administrator will view the logs.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/43b8cfb4-f875-432b-8e3b-52653fdee87c | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/43b8cfb4-f875-432b-8e3b-52653fdee87c | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/43b8cfb4-f875-432b-8e3b-52653fdee87c - Exploit, Third Party Advisory |
28 May 2021, 18:03
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mlfactory:dsgvo_all_in_one_for_wp:*:*:*:*:*:wordpress:*:* | |
References | (CONFIRM) https://wpscan.com/vulnerability/43b8cfb4-f875-432b-8e3b-52653fdee87c - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.1 |
24 May 2021, 12:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
24 May 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-05-24 11:15
Updated : 2024-11-21 05:52
NVD link : CVE-2021-24294
Mitre link : CVE-2021-24294
CVE.ORG link : CVE-2021-24294
JSON object : View
Products Affected
mlfactory
- dsgvo_all_in_one_for_wp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')