CVE-2021-24176
Summary
| CVE | CVE-2021-24176 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-05 19:15:00 UTC |
| Updated | 2021-10-18 12:06:00 UTC |
| Description | The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jh 404 Logger Project | Jh 404 Logger | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS) Security Vulnerability | CONFIRM | wpscan.com | |
| My First CVE-2021-24176 - Ganofins Blog | MISC | ganofins.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ganesh Bagaria
There are currently no legacy QID mappings associated with this CVE.