CVE-2021-24276
MEDIUM NUCLEIContact Form by Supsystic < 1.7.15 - Reflected Cross-Site Scripting via Tab Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24276. PoCs published by 0xB9. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the Contact Form by Supsystic WordPress plugin (version 1.7.14) via the unsanitized 'tab' parameter in the admin page. The PoC uses a crafted URL to trigger an XSS payload via CSS animation events.
Description
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the Contact Form by Supsystic WordPress plugin (version 1.7.14) via the unsanitized 'tab' parameter in the admin page. The PoC uses a crafted URL to trigger an XSS payload via CSS animation events.
Nuclei Templates (1)
http.html:/wp-content/plugins/contact-form-plugin/
body=/wp-content/plugins/contact-form-plugin/
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N