Record summary

CVE-2021-24298 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Simple Giveaways – Grow your business, email lists and traffic with contests

Browse Igor Benic / Simple Giveaways – Grow your business, email lists and traffic with contests
CVE List2.36.2 to < 2.36.2affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24298Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 477 B

GitHub

PoC details
GitHubCVE-2021-24298Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 477 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Simple Giveaways <2.36.2 - Cross-Site ScriptingCVSS 6.1

WordPress Simple Giveaways plugin before 2.36.2 contains a cross-site scripting vulnerability via the method and share GET parameters of the Giveaway pages, which are not sanitized, validated, or escaped before being output back in the pages.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential theft of sensitive information or unauthorized actions.

Remediation

Update to the latest version of the WordPress Simple Giveaways plugin (2.36.2 or higher) to mitigate the vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2021cvewpscanwordpressxsswp-pluginibenicvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ibenic:simple_giveaways:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3