Pular para o conteúdo
Ver todas as ameaças

CVE-2021-24879

Alvo: Não informado

Descrição

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2021-24879
Tags
Nâo informado
Data de publicação
07/02/2022
Última atualização
11/03/2022
Pontuação em CVSS 3.0
8.8
Alto
plugins premium WordPress