CVE-2021-36823

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cusmin:absolutely_glamorous_custom_admin:*:*:*:*:*:wordpress:*:*

History

29 Apr 2024, 09:15

Type Values Removed Values Added
Summary (en) Auth. Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin <= 6.8 versions. (en) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.

29 Sep 2021, 20:01

Type Values Removed Values Added
CPE cpe:2.3:a:cusmin:absolutely_glamorous_custom_admin:*:*:*:*:*:wordpress:*:*
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 8.2
References (CONFIRM) https://plugins.svn.wordpress.org/ag-custom-admin/trunk/changelog.txt - (CONFIRM) https://plugins.svn.wordpress.org/ag-custom-admin/trunk/changelog.txt - Release Notes, Third Party Advisory
References (MISC) https://patchstack.com/database/vulnerability/ag-custom-admin/wordpress-absolutely-glamorous-custom-admin-plugin-6-8-authenticated-stored-cross-site-scripting-xss-vulnerability - (MISC) https://patchstack.com/database/vulnerability/ag-custom-admin/wordpress-absolutely-glamorous-custom-admin-plugin-6-8-authenticated-stored-cross-site-scripting-xss-vulnerability - Third Party Advisory
References (MISC) https://www.youtube.com/watch?v=tnyIIWntOww - (MISC) https://www.youtube.com/watch?v=tnyIIWntOww - Exploit, Third Party Advisory

23 Sep 2021, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-23 17:15

Updated : 2024-04-29 09:15


NVD link : CVE-2021-36823

Mitre link : CVE-2021-36823

CVE.ORG link : CVE-2021-36823


JSON object : View

Products Affected

cusmin

  • absolutely_glamorous_custom_admin
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')