Record summary

CVE-2021-24409 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.8 to < 2.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPrismatic < 2.8 - Cross-Site ScriptingCVSS 6.1

The plugin does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or session hijacking.

Remediation

Fixed in version 2.8

WeaknessesCWE-79
AuthorsHarsh
Template tagscve2021cvewpscanwordpresswpwp-pluginxssprismaticauthenticatedplugin-planetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:plugin-planet:prismatic:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/prismatic
FOFA: body=/wp-content/plugins/prismatic

Source: ProjectDiscovery

References

2