Vulnerability CVE-2021-24536


Published: 2021-08-16

Description:
The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issue

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Custom login redirect project -> Custom login redirect 

 References:
https://wpscan.com/vulnerability/e1ca9978-a44d-4717-b963-acaf56258fc9

Copyright 2024, cxsecurity.com

 

Back to Top