CVE-2021-24558
Summary
| CVE | CVE-2021-24558 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-23 12:15:00 UTC |
| Updated | 2021-08-27 17:24:00 UTC |
| Description | The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | 3.7designs | Project Status | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wp-plugin : project-status | Code Vigilant : to err is human.. To fix is Humanity | MISC | codevigilant.com | |
| Attention Required! | Cloudflare | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Shreya Pohekar of Codevigilant Project
There are currently no legacy QID mappings associated with this CVE.