Record summary

CVE-2021-24563 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 2 curated repository PoCs.

Description

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Frontend Uploader

CVE List1.3.2 to ≤ 1.3.2affected

Proofs of concept

4

Catalogued exploits

ExploitDBWordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)ExploitDB exploitby Veshraj GhimireNot analyzed1 file
ExploitDB

PoC details

Curated repository PoCs

GitHubCVE-2021-24563Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 2.6 KiB

GitHub

PoC details
GitHubCVE-2021-24563Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 2.6 KiB

GitHub

PoC details

Repository PoCs

GitHubV35HR4J/CVE-2021-24563Repository PoCby V35HR4JStars: 1Not analyzed1 file

2.3 KiB

GitHub

PoC details

References

3