CVE-2021-24335
Car Repair Services < 4.0 - Unauthenticated Reflected XSS & XFS
Record summary
CVE-2021-24335 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.
Description
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Car Repair Services & Auto Mechanic | CVE List | 4.0 to < 4.0 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24335Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24335Curated repository PoCby yubsyStars: 112Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-Site ScriptingCVSS 6.1
WordPress Car Repair Services & Auto Mechanic before 4.0 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the serviceestimatekey parameter before outputting it back in the page.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, leading to potential data theft, session hijacking, or defacement.
Remediation
Update to the latest version of the WordPress Car Repair Services & Auto Mechanic Theme (version 4.0 or higher) to mitigate the XSS vulnerability.
Source: ProjectDiscovery