Record summary

CVE-2021-24664 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

School Management System – WPSchoolPress

CVE List2.1.17 to < 2.1.17affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)ExploitDB exploitby Davide TaraschiNot analyzed1 file
ExploitDB

PoC details

References

3