CVE-2021-24176 Information

Description

The JH 404 Logger WordPress plugin through 1.1 doesn’t sanitise the referer and path of 404 pages when they are output in the dashboard which leads to executing arbitrary JavaScript code in the WordPress dashboard.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585 https://ganofins.com/blog/my-first-cve-2021-24176/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: