CVE-2021-24409
Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-24409 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PrismaticBrowse Jeff Starr / Prismatic | CVE List | 2.8 to < 2.8 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMPrismatic < 2.8 - Cross-Site ScriptingCVSS 6.1
The plugin does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or session hijacking.
Remediation
Fixed in version 2.8
Source: ProjectDiscovery