nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24797 CVE-2021-24797
MEDIUM
Tickera < 3.4.8.3 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-24797 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Tickera – WordPress Event Ticketing | CVE List | 3.4.8.3 to < 3.4.8.3 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24797Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24797Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/0eb07cc8-8a19-4e01-ab90-844495413453