CVE-2021-24504
Summary
| CVE | CVE-2021-24504 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-02 11:15:00 UTC |
| Updated | 2023-11-07 03:31:00 UTC |
| Description | The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated) |
Risk And Classification
Problem Types: CWE-352 | CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wplearnmanager | Wp Learn Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WP LMS <= 1.1.2 - Stored Cross-Site Scripting (XSS) WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Mohammed Adam
There are currently no legacy QID mappings associated with this CVE.