CVE-2021-24878
SupportCandy < 2.2.7 - Reflected Cross-Site Scripting
Record summary
CVE-2021-24878 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 5, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SupportCandy – Helpdesk & Support Ticket System | CVE List | 2.2.7 to < 2.2.7 | affected |
supportcandyBrowse supportcandy / supportcandy | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMSupportCandy < 2.2.7 - Reflected Cross-Site ScriptingCVSS 6.1
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue
Impact
Attackers can inject malicious JavaScript via reflected XSS in pages with wpsc_create_ticket shortcode, potentially stealing user session cookies or manipulating support ticket data.
Remediation
Fixed in 2.2.7
Source: ProjectDiscovery