Record summary

CVE-2021-24335 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Car Repair Services & Auto Mechanic

CVE List4.0 to < 4.0affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24335Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 421 B

GitHub

PoC details
GitHubCVE-2021-24335Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 421 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-Site ScriptingCVSS 6.1

WordPress Car Repair Services & Auto Mechanic before 4.0 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the serviceestimatekey parameter before outputting it back in the page.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update to the latest version of the WordPress Car Repair Services & Auto Mechanic Theme (version 4.0 or higher) to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2021cvewordpressxsswp-pluginwpscansmartdatasoftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:smartdatasoft:car_repair_services_\&_auto_mechanic:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5