Record summary

CVE-2021-24797 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Tickera – WordPress Event Ticketing

CVE List3.4.8.3 to < 3.4.8.3affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24797Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 723 B

GitHub

PoC details
GitHubCVE-2021-24797Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 723 B

GitHub

PoC details

References

2