mirror of
https://github.com/0xMarcio/cve.git
synced 2025-12-30 04:49:42 +00:00
20 lines
1.0 KiB
Markdown
20 lines
1.0 KiB
Markdown
### [CVE-2021-24291](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24291)
|
||

|
||

|
||
&color=brighgreen)
|
||
|
||
### Description
|
||
|
||
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://packetstormsecurity.com/files/162227/
|
||
- https://wpscan.com/vulnerability/cfb982b2-8b6d-4345-b3ab-3d2b130b873a
|
||
|
||
#### Github
|
||
- https://github.com/ARPSyndicate/cvemon
|
||
- https://github.com/ARPSyndicate/kenzer-templates
|
||
|