PT-2021-15836 · WordPress · Redi Restaurant Reservation
Bastijn Ouwendijk
·
Published
2021-05-17
·
Updated
2021-05-24
·
CVE-2021-24299
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ReDi Restaurant Reservation WordPress plugin versions prior to 21.0426
Description
The issue concerns a lack of proper input validation in the 'Comment' field of the restaurant reservation form, allowing an unauthenticated user to store XSS payloads. These payloads are executed when a plugin user visits the 'Upcoming' page, which loads an external website https://upcoming.reservationdiary.eu/ in an iframe, and the stored reservation with the XSS payload is loaded.
Recommendations
For versions prior to 21.0426, update to version 21.0426 or later to resolve the issue. As a temporary workaround, consider disabling the 'Comment' field in the reservation form until a patch is available. Restrict access to the 'Upcoming' page to minimize the risk of exploitation. Avoid using the 'Comment' field in the affected reservation form until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redi Restaurant Reservation