nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24756 CVE-2021-24756
MEDIUM
WP System Log < 1.0.21 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-24756 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP System Log | CVE List | 1.0.21 to < 1.0.21 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24756Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2021-24756Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/0cea0717-8f54-4f1c-b3ee-aff7dd91bf59