CVE-2021-24563
MEDIUMFrontend Uploader < 1.3.2 - Unauthenticated Stored Cross-Site Scripting via HTML File Upload
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-24563. PoCs published by Veshraj Ghimire, V35HR4J.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in WordPress Plugin Frontend Uploader 1.3.2, allowing unauthenticated users to upload malicious HTML files containing JavaScript, which executes when accessed.
Description
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in WordPress Plugin Frontend Uploader 1.3.2, allowing unauthenticated users to upload malicious HTML files containing JavaScript, which executes when accessed.
The repository provides a functional proof-of-concept for CVE-2021-24563, demonstrating an unauthenticated stored XSS vulnerability in Frontend Uploader <= 1.3.2 via HTML file upload. The PoC includes a detailed HTTP request to exploit the vulnerability and trigger the XSS payload.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N