The Admin Columns Free WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1, rendered input on the posted pages with improper input validation on the value passed into the field 'Label' parameter, by taking this as an advantage an authenticated attacker can supply a crafted arbitrary script and execute it.
References
Link | Resource |
---|---|
https://github.com/codepress/admin-columns/commit/b45571ed21d574d13687213a5002e0c68e4442c7 | |
https://wpscan.com/vulnerability/05427156-4d5c-4aeb-add8-1c574fda5c28 | Exploit Third Party Advisory |
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-24366 | Exploit Third Party Advisory |
https://github.com/codepress/admin-columns/commit/b45571ed21d574d13687213a5002e0c68e4442c7 | |
https://wpscan.com/vulnerability/05427156-4d5c-4aeb-add8-1c574fda5c28 | Exploit Third Party Advisory |
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-24366 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/codepress/admin-columns/commit/b45571ed21d574d13687213a5002e0c68e4442c7 - | |
References | () https://wpscan.com/vulnerability/05427156-4d5c-4aeb-add8-1c574fda5c28 - Exploit, Third Party Advisory | |
References | () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-24366 - Exploit, Third Party Advisory |
25 Jun 2021, 12:34
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://wpscan.com/vulnerability/05427156-4d5c-4aeb-add8-1c574fda5c28 - Exploit, Third Party Advisory | |
References | (MISC) https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-24366 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:admincolumns:admin_columns:*:*:*:*:free:wordpress:*:* cpe:2.3:a:admincolumns:admin_columns:*:*:*:*:pro:wordpress:*:* |
|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.4 |
21 Jun 2021, 20:27
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-21 20:15
Updated : 2024-11-21 05:52
NVD link : CVE-2021-24366
Mitre link : CVE-2021-24366
CVE.ORG link : CVE-2021-24366
JSON object : View
Products Affected
admincolumns
- admin_columns
CWE
No CWE.