CVE-2021-24274
MEDIUM NUCLEIUltimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site Scripting via Tab Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24274. PoCs published by 0xB9. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in WordPress Plugin Ultimate Maps 1.2.4 via the unsanitized 'tab' parameter. The PoC uses a crafted URL to trigger an XSS payload via CSS animation and JavaScript event handler.
Description
The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in WordPress Plugin Ultimate Maps 1.2.4 via the unsanitized 'tab' parameter. The PoC uses a crafted URL to trigger an XSS payload via CSS animation and JavaScript event handler.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N