Vulnerability Description
The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marmoset | Marmoset Viewer | < 1.9.3 |
Related Weaknesses (CWE)
References
- https://johnjhacking.com/blog/cve-2021-24495-improper-neutralization-of-input-duExploitThird Party Advisory
- https://wpscan.com/vulnerability/d11b79a3-f762-49ab-b7c8-3174624d7638ExploitThird Party Advisory
- https://johnjhacking.com/blog/cve-2021-24495-improper-neutralization-of-input-duExploitThird Party Advisory
- https://wpscan.com/vulnerability/d11b79a3-f762-49ab-b7c8-3174624d7638ExploitThird Party Advisory
FAQ
What is CVE-2021-24495?
CVE-2021-24495 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issu...
How severe is CVE-2021-24495?
CVE-2021-24495 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24495?
Check the references section above for vendor advisories and patch information. Affected products include: Marmoset Marmoset Viewer.