CVE-2024-10146
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
Record summary
CVE-2024-10146 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 14, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Simple File ListDefault status: unaffected | CVE List | Before 6.1.13 | affected |
simple_file_listBrowse simplefilelist / simple_file_listDefault status: unknown | CVE List | Before 6.1.13 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSimple File List < 6.1.13 - Reflected Cross-Site ScriptingCVSS 5.4
Simple File List WordPress plugin \u003C 6.1.13 contains a reflected cross-site scripting caused by unsanitized URL output in an attribute, letting attackers execute malicious scripts in admin browsers, exploit requires victim to be an admin.
Impact
Attackers can execute malicious scripts in admin browsers, potentially leading to session hijacking or privilege escalation.
Remediation
Update to version 6.1.13 or later.
Source: ProjectDiscovery