Title: Stored Cross-Site Scripting in JetEngine Wordpress Plugin
CVE ID: CVE-2021-38607
CVSSv3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Vendor: Crocoblock
Products: JetEngine
Advisory Release Date: 16-12-2021
Advisory URL: https://labs.integrity.pt/advisories/cve-2021-38607
Credits: Discovery by Bruno Barreirinhas <bb[at]integrity.pt>
Crocoblock JetEngine plugin for Wordpress is vulnerable to stored XSS in custom form inputs. The JavaScript payload will be executed when authorized Users or Administrators attempt to update the data submitted using the custom form.
© 2024 INTEGRITY S.A. All rights reserved. | Cookie Policy