Record summary

CVE-2021-24510 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

MF Gig Calendar

Default status: unaffected

CVE ListBefore 1.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress MF Gig Calendar <=1.1 - Cross-Site ScriptingCVSS 6.1

WordPress MF Gig Calendar plugin 1.1 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize or escape the id GET parameter before outputting back in the admin dashboard when editing an event.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update to the latest version of WordPress MF Gig Calendar plugin (>=1.2) which includes proper input sanitization and validation.

WeaknessesCWE-79
AuthorsdhiyaneshDK
Template tagscve2021cvewp-pluginauthenticatedwpscanwordpressmf_gig_calendar_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:mf_gig_calendar_project:mf_gig_calendar:*:*:*:*:wordpress:*:*:*

Source: ProjectDiscovery

References

2