CVE-2021-24510

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mf_gig_calendar_project:mf_gig_calendar:*:*:*:*:wordpress:*:*:*

History

20 Apr 2023, 09:15

Type Values Removed Values Added
Summary The MF Gig Calendar WordPress plugin through 1.1 does not sanitise or escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

23 Sep 2021, 13:18

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/715721b0-13a1-413a-864d-2380f38ecd39 - (MISC) https://wpscan.com/vulnerability/715721b0-13a1-413a-864d-2380f38ecd39 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:a:mf_gig_calendar_project:mf_gig_calendar:*:*:*:*:wordpress:*:*:*

13 Sep 2021, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-13 18:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-24510

Mitre link : CVE-2021-24510

CVE.ORG link : CVE-2021-24510


JSON object : View

Products Affected

mf_gig_calendar_project

  • mf_gig_calendar
CWE

No CWE.