CVE-2021-24275
MEDIUM NUCLEIPopup by Supsystic < 1.10.5 - Reflected Cross-Site Scripting via Tab Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24275. PoCs published by 0xB9. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the WordPress Plugin Popup 1.10.4 by injecting malicious JavaScript via the unsanitized 'tab' parameter in the admin page URL. The PoC triggers an alert dialog as proof of concept.
Description
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the WordPress Plugin Popup 1.10.4 by injecting malicious JavaScript via the unsanitized 'tab' parameter in the admin page URL. The PoC triggers an alert dialog as proof of concept.
Nuclei Templates (1)
http.html:/wp-content/plugins/popup-by-supsystic
body=/wp-content/plugins/popup-by-supsystic
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N