Record summary

CVE-2021-24878 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 5, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

SupportCandy – Helpdesk & Support Ticket System

CVE List2.2.7 to < 2.2.7affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMSupportCandy < 2.2.7 - Reflected Cross-Site ScriptingCVSS 6.1

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue

Impact

Attackers can inject malicious JavaScript via reflected XSS in pages with wpsc_create_ticket shortcode, potentially stealing user session cookies or manipulating support ticket data.

Remediation

Fixed in 2.2.7

WeaknessesCWE-79
Authorspopcorn94
Template tagscvecve2021wordpresswpscanwp-pluginsupportcandyxssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:supportcandy:supportcandy:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/supportcandy/"

Source: ProjectDiscovery

References

2