Record summary

CVE-2021-25078 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Affiliates Manager

CVE List2.9.0 to < 2.9.0affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-25078Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 587 B

GitHub

PoC details
GitHubCVE-2021-25078Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 587 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMAffiliates Manager < 2.9.0 - Cross Site ScriptingCVSS 6.1

The plugin does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of an authenticated user, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Fixed in version 2.9.0

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2021cvewpwordpressauthenticatedaffiliates-managerwp-pluginxsswpscanwpaffiliatemanagervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wpaffiliatemanager:affiliates_manager:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3