PT-2021-15971 · WordPress · Youzify
Fergustr4N
+1
·
Published
2021-08-02
·
Updated
2021-08-10
·
CVE-2021-24443
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin versions prior to 1.0.7
Description
The issue concerns the About Me widget's Biography field, which does not properly sanitise input. This allows any authenticated user to set Cross-Site Scripting payloads, potentially leading to unauthorised access to the admin side of the blog when an admin views the affected user profile.
Recommendations
For versions prior to 1.0.7, update to version 1.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the About Me widget's Biography field to prevent low-privilege users from setting malicious payloads.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Youzify