PT-2021-15759 · WordPress · Openid Connect Generic Client
Austin Bentley
·
Published
2021-05-05
·
Updated
2021-05-13
·
CVE-2021-24214
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenID Connect Generic Client WordPress plugin versions 3.8.0 through 3.8.1
Description:
The issue is related to a reflected Cross-Site Scripting problem. It occurs because the login error is not properly sanitized when output back in the login form. This issue can be exploited without authentication and with the default configuration.
Recommendations:
For versions 3.8.0 and 3.8.1, update to a version that addresses this issue, as the current versions do not properly sanitise the login error, leading to a reflected Cross-Site Scripting issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openid Connect Generic Client