Jeff Starr Vulnerabilities and Affected Products
Vulnerabilities associated with Prismatic.
Products
Clear product- Simple Ajax Chat (WordPress plugin)3 vulnerabilities
- Dashboard Widgets Suite2 vulnerabilities
- Prismatic2 vulnerabilities
- User Submitted Posts2 vulnerabilities
- Contact Form X (WordPress plugin)1 vulnerability
- Head Meta Data1 vulnerability
- Simple Ajax Chat1 vulnerability
- Simple Blog Stats1 vulnerability
- Simple Download Counter1 vulnerability
- Simple Statistics for Feeds1 vulnerability
- Theme Switcha1 vulnerability
- User Submitted Posts – Enable Users to Submit Posts from the Front End1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24409MEDIUM | Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | CVSS6.1v3.1 | EPSS1.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-24408MEDIUM | Prismatic < 2.8 - Contributor+ Stored XSSThe Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability. CWE-79Jul 12, 2021 | CVSS5.4v3.1 | EPSS0.624% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |