CVE-2021-24383
Summary
| CVE | CVE-2021-24383 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-21 20:15:00 UTC |
| Updated | 2023-05-24 00:49:00 UTC |
| Description | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Codecabin | Wp Google Maps | All | All | All | All |
| Application | Codecabin | Wp Go Maps | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS) Security Vulnerability | CONFIRM | wpscan.com | |
| WordPress WP Google Maps 8.1.11 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Mohammed Adam
There are currently no legacy QID mappings associated with this CVE.